Remote XSS Vulnerability in HPE Integrated Lights-Out Products
CVE-2021-29201
Key Information:
- Vendor
- HP
- Vendor
- CVE Published:
- 25 May 2021
Summary
A remote XSS vulnerability was identified in HPE Integrated Lights-Out (iLO) and HPE SimpliVity products. This vulnerability can potentially allow attackers to inject malicious scripts, leading to unauthorized access or data manipulation. It affects various versions of iLO 4, iLO 5, and several SimpliVity models prior to version 2.78. Ensuring timely updates and patching is essential to mitigate associated risks.
Affected Version(s)
HPE Integrated Lights-Out 4 (iLO 4) For HPE Gen9 servers; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers Prior to HPE Integrated Lights-Out 4 (iLO 4) version 2.78
HPE Integrated Lights-Out 4 (iLO 4) For HPE Gen9 servers; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers Prior to HPE Integrated Lights-Out 5 (iLO 5) version 2.44
HPE Integrated Lights-Out 4 (iLO 4) For HPE Gen9 servers; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers = unspecified
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved