Remote XSS Vulnerability in HPE Integrated Lights-Out Products
CVE-2021-29201

4.8MEDIUM

Summary

A remote XSS vulnerability was identified in HPE Integrated Lights-Out (iLO) and HPE SimpliVity products. This vulnerability can potentially allow attackers to inject malicious scripts, leading to unauthorized access or data manipulation. It affects various versions of iLO 4, iLO 5, and several SimpliVity models prior to version 2.78. Ensuring timely updates and patching is essential to mitigate associated risks.

Affected Version(s)

HPE Integrated Lights-Out 4 (iLO 4) For HPE Gen9 servers; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers Prior to HPE Integrated Lights-Out 4 (iLO 4) version 2.78

HPE Integrated Lights-Out 4 (iLO 4) For HPE Gen9 servers; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers Prior to HPE Integrated Lights-Out 5 (iLO 5) version 2.44

HPE Integrated Lights-Out 4 (iLO 4) For HPE Gen9 servers; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers = unspecified

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.