Remote XSS Vulnerability in HPE Integrated Lights-Out and SimpliVity Products
CVE-2021-29204
Key Information:
- Vendor
- HP
- Vendor
- CVE Published:
- 25 May 2021
Summary
A remote cross-site scripting (XSS) vulnerability has been identified in multiple HPE products, enabling attackers to inject malicious scripts via the web interface. This could allow unauthorized actions to be performed on behalf of users, potentially compromising sensitive information and leading to unauthorized access within the affected systems. The vulnerable versions include HPE Integrated Lights-Out 4 (iLO 4), several models of HPE SimpliVity, and iLO 5 for Gen10 servers, with a recommended update to version 2.78 or higher for resolution. For more details, refer to HPE's support document for guidance on securing your systems.
Affected Version(s)
HPE Integrated Lights-Out 4 (iLO 4) For HPE Gen9 servers; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers Prior to HPE Integrated Lights-Out 4 (iLO 4) version 2.78
HPE Integrated Lights-Out 4 (iLO 4) For HPE Gen9 servers; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers Prior to HPE Integrated Lights-Out 5 (iLO 5) version 2.44
HPE Integrated Lights-Out 4 (iLO 4) For HPE Gen9 servers; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers = unspecified
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved