Remote Code Execution Vulnerability in HP Integrated Lights-Out 3 and 4
CVE-2013-2338

Currently unrated

Key Information:

Vendor
HP
Vendor
CVE Published:
14 June 2013

Summary

An unspecified vulnerability in HP Integrated Lights-Out 3 (iLO3) and iLO4 firmware prior to versions 1.57 and 1.22 respectively, poses a security risk that allows attackers to remotely execute arbitrary code. This vulnerability manifests when Single-Sign-On (SSO) functionality is utilized, thus potentially compromising server management systems and sensitive operations.

References

EPSS Score

26% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.