QID 731099

Date Published: 2024-01-31

QID 731099: Hewlett Packard Enterprise (HPE) OneView Multiple Vulnerabilities (HPESBGN04586)

HPE OneView is an IT infrastructure management software that streamlines IT operations and controls all of your systems via a single global dashboard.

Potential security vulnerabilities have been identified in Hewlett Packard Enterprise OneView Software. These vulnerabilities could be exploited to allow remote code execution, local privilege escalation, Server-Side Request Forgery, Denial-of-Service and unauthenticated Restore.

Affected Version
HPE OneView - All versions prior to 8.70
QID detection logic (Un-Auth)
This qid send GET request to /rest/appliance/nodeinfo/version to check software version

These vulnerabilities could be exploited to allow remote code execution, local privilege escalation, Server-Side Request Forgery, Denial-of-Service and unauthenticated Restore.

  • CVSS V3 rated as Critical - 9 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Vendor has released patched version. Please refer to HPE advisory: here for patching details

    CVEs related to QID 731099

    Software Advisories
    Advisory ID Software Component Link
    HPESBGN04586 URL Logo support.hpe.com/hpesc/public/docDisplay?docId=emr_na-hpesbgn04586en_us&hprpt_id=ALERT_HPE_3062067&jumpid=em_pom8nu6hj_aid-520066529