PT-2017-3653 · Hewlett Packard · Hpe Integrated Lights-Out 4+1

Skelsec

·

Published

2017-08-23

·

Updated

2025-12-30

·

CVE-2017-12542

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: HPE Integrated Lights-out 4 (iLO 4) versions prior to 2.53
Description: A vulnerability in the authentication procedure of HPE Integrated Lights-out 4 (iLO 4) allows an attacker to bypass authentication and execute arbitrary code remotely.
Recommendations: For HPE Integrated Lights-out 4 (iLO 4) versions prior to 2.53, update to version 2.53 or later to resolve the issue.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-00779
CVE-2017-12542
HPILOACCCVE201712542

Affected Products

Hpe Integrated Lights-Out 4
Hpe Ilo