PT-2016-5925 · Hewlett Packard · Hpe Integrated Lights-Out 3+1
Publicado
2016-08-30
·
Atualizado
2016-11-28
·
CVE-2016-4379
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
HPE Integrated Lights-Out 3 (iLO3) versions prior to 1.88
Description
The issue is related to the TLS implementation, which does not properly use a MAC protection mechanism in conjunction with CBC padding. This allows remote attackers to obtain sensitive information via a padding-oracle attack, also known as a Vaudenay attack. The vulnerability could be remotely exploited using TLS CBC Padding and MAC Errors, resulting in disclosure of information.
Recommendations
For HPE Integrated Lights-Out 3 (iLO3) versions prior to 1.88, update the firmware to version 1.88 or later to resolve the issue.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Hpe Integrated Lights-Out 3
Hpe Ilo