Vulnerabilities > CVE-2017-8979 - Unspecified vulnerability in HP Integrated Lights-Out 2 Firmware 2.29
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
Security vulnerabilities in the HPE Integrated Lights-Out 2 (iLO 2) firmware could be exploited remotely to allow authentication bypass, code execution, and denial of service.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 1 | |
Hardware | 1 |
Nessus
NASL family | CGI abuses |
NASL id | ILO_HPESBHF_03797.NASL |
description | A remote command execution vulnerability exists in Integrated Lights-Out 2 (iLO 2) version 2.29 due to insufficient access control. An unauthenticated, remote attacker can exploit this to bypass authentication, execute arbitrary commands or cause a denial of service. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 122423 |
published | 2019-02-26 |
reporter | This script is Copyright (C) 2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/122423 |
title | iLO 2 2.29 Remote Code Execution Vulnerability |
code |
|
References
- https://support.hpe.com/hpsc/doc/public/display?docId=hpesbhf03797en_us
- https://support.hpe.com/hpsc/doc/public/display?docId=hpesbhf03797en_us
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03797en_us
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03797en_us