Authentication Bypass Vulnerability in HPE Integrated Lights-Out 5 and 6
CVE-2023-50272

9.8CRITICAL

What is CVE-2023-50272?

A security vulnerability has been discovered in HPE Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 6 (iLO 6) that may allow remote attackers to bypass authentication mechanisms. This can potentially lead to unauthorized access and control over affected systems. It is critical for users to apply any available patches and updates to safeguard their systems against this flaw. For more details, refer to HPE's official security bulletin.

Affected Version(s)

HPE Integrated Lights-out 5 (iLO 5), HPE Integrated Lights-out 6 (iLO 6), iLO 5 - v2.63 through versions prior to v3.00

HPE Integrated Lights-out 5 (iLO 5), HPE Integrated Lights-out 6 (iLO 6), iLO 6 - v1.05 through versions prior to v1.55

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.