PT-2014-1983 · Hewlett Packard · Hpe Ilo 4+3
Aleksandr Tlyapov
·
Published
2014-09-22
·
Updated
2019-10-09
·
CVE-2014-7876
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
HP iLO 2 versions prior to 2.27
HP iLO 4 versions prior to 2.03
HP iLO Chassis Management (CM) firmware versions prior to 1.30
Description
The issue is caused by a stack buffer overflow in the server management mechanism. This allows a remote attacker to potentially execute arbitrary code, gain privileges, or cause a denial of service. The vulnerability can be exploited remotely.
Recommendations
For HP iLO 2 versions prior to 2.27, update the firmware to version 2.27 or later.
For HP iLO 4 versions prior to 2.03, update the firmware to version 2.03 or later.
For HP iLO Chassis Management (CM) firmware versions prior to 1.30, update the firmware to version 1.30 or later.
Fix
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hp Ilo 2
Hpe Ilo 4
Hp Ilo Chassis Management
Hpe Ilo