CVE-2013-2338: Critical severity hp integrated lights-out 3 vulnerability
Unspecified vulnerability on HP Integrated Lights-Out 3 (aka iLO3) cards with firmware before 1.57 and 4 (aka iLO4) cards with firmware before 1.22, when Single-Sign-On (SSO) is used, allows remote attackers to execute arbitrary code via unknown vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2338?
CVE-2013-2338 is considered critical as it allows remote attackers to execute arbitrary code on affected HP Integrated Lights-Out cards.
How do I fix CVE-2013-2338?
To fix CVE-2013-2338, upgrade the firmware of HP Integrated Lights-Out 3 to version 1.57 or later, or HP Integrated Lights-Out 4 to version 1.22 or later.
What systems are affected by CVE-2013-2338?
CVE-2013-2338 affects HP Integrated Lights-Out 3 and 4 cards with specific firmware versions prior to the latest updates.
Can CVE-2013-2338 be exploited without authentication?
Yes, CVE-2013-2338 can potentially be exploited by remote attackers without requiring authentication if Single-Sign-On is enabled.
Is there a workaround for CVE-2013-2338?
Disabling Single-Sign-On on affected HP Integrated Lights-Out cards may reduce the risk of exploitation while waiting for firmware updates.