Remote XSS Vulnerability in HPE Integrated Lights-Out and SimpliVity Products
CVE-2021-29206
Key Information:
- Vendor
- HP
- Vendor
- CVE Published:
- 25 May 2021
Summary
A remote cross-site scripting vulnerability exists in HPE Integrated Lights-Out (iLO) and SimpliVity products, allowing attackers to inject malicious scripts via orchestrated requests. This could potentially lead to unauthorized actions or data exposure for users interacting with affected interfaces. This vulnerability impacts several versions of HPE's iLO 4, iLO 5, and SimpliVity products prior to version 2.78, highlighting a significant security risk for enterprises utilizing these systems.
Affected Version(s)
HPE Integrated Lights-Out 4 (iLO 4) For HPE Gen9 servers; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers Prior to HPE Integrated Lights-Out 4 (iLO 4) version 2.78
HPE Integrated Lights-Out 4 (iLO 4) For HPE Gen9 servers; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers Prior to HPE Integrated Lights-Out 5 (iLO 5) version 2.44
HPE Integrated Lights-Out 4 (iLO 4) For HPE Gen9 servers; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers = unspecified
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved