PT-2016-5925 · Hewlett Packard · Hpe Integrated Lights-Out 3+1

Publicado

2016-08-30

·

Atualizado

2016-11-28

·

CVE-2016-4379

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions HPE Integrated Lights-Out 3 (iLO3) versions prior to 1.88
Description The issue is related to the TLS implementation, which does not properly use a MAC protection mechanism in conjunction with CBC padding. This allows remote attackers to obtain sensitive information via a padding-oracle attack, also known as a Vaudenay attack. The vulnerability could be remotely exploited using TLS CBC Padding and MAC Errors, resulting in disclosure of information.
Recommendations For HPE Integrated Lights-Out 3 (iLO3) versions prior to 1.88, update the firmware to version 1.88 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-4379

Produtos afetados

Hpe Integrated Lights-Out 3
Hpe Ilo