Remote XSS Vulnerability in HPE Integrated Lights-Out 4 and 5
CVE-2021-29207

4.8MEDIUM

Summary

A remote XSS vulnerability has been identified in HPE Integrated Lights-Out (iLO 4 and iLO 5) as well as various HPE SimpliVity models. Attackers can exploit this vulnerability to inject arbitrary scripts into the affected systems, potentially compromising sensitive data and system integrity. The vulnerability impacts versions prior to 2.78, highlighting the need for users to update their systems to mitigate the risk of unauthorized access and control.

Affected Version(s)

HPE Integrated Lights-Out 4 (iLO 4) For HPE Gen9 servers; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers Prior to HPE Integrated Lights-Out 4 (iLO 4) version 2.78

HPE Integrated Lights-Out 4 (iLO 4) For HPE Gen9 servers; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers Prior to HPE Integrated Lights-Out 5 (iLO 5) version 2.44

HPE Integrated Lights-Out 4 (iLO 4) For HPE Gen9 servers; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers = unspecified

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.