Remote XSS Vulnerability in HPE Integrated Lights-Out 4 and 5
CVE-2021-29207
Key Information:
- Vendor
- HP
- Vendor
- CVE Published:
- 25 May 2021
Summary
A remote XSS vulnerability has been identified in HPE Integrated Lights-Out (iLO 4 and iLO 5) as well as various HPE SimpliVity models. Attackers can exploit this vulnerability to inject arbitrary scripts into the affected systems, potentially compromising sensitive data and system integrity. The vulnerability impacts versions prior to 2.78, highlighting the need for users to update their systems to mitigate the risk of unauthorized access and control.
Affected Version(s)
HPE Integrated Lights-Out 4 (iLO 4) For HPE Gen9 servers; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers Prior to HPE Integrated Lights-Out 4 (iLO 4) version 2.78
HPE Integrated Lights-Out 4 (iLO 4) For HPE Gen9 servers; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers Prior to HPE Integrated Lights-Out 5 (iLO 5) version 2.44
HPE Integrated Lights-Out 4 (iLO 4) For HPE Gen9 servers; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers = unspecified
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved