First published: Fri Jun 14 2013(Updated: )
Unspecified vulnerability on HP Integrated Lights-Out 3 (aka iLO3) cards with firmware before 1.57 and 4 (aka iLO4) cards with firmware before 1.22, when Single-Sign-On (SSO) is used, allows remote attackers to execute arbitrary code via unknown vectors.
Credit: hp-security-alert@hp.com
Affected Software | Affected Version | How to fix |
---|---|---|
HP Integrated Lights-Out 3 | <=1.55 | |
HP Integrated Lights-Out 3 | =1.00 | |
HP Integrated Lights-Out 3 | =1.05 | |
HP Integrated Lights-Out 3 | =1.20 | |
HP Integrated Lights-Out 3 | =1.26 | |
HP Integrated Lights-Out 3 | =1.28 | |
HP Integrated Lights-Out 3 | =1.50 | |
HP Integrated Lights-Out 4 mRCA firmware | <=1.20 | |
HP Integrated Lights-Out 4 mRCA firmware | =1.11 | |
HP Integrated Lights-Out 4 mRCA firmware | =1.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-2338 is considered critical as it allows remote attackers to execute arbitrary code on affected HP Integrated Lights-Out cards.
To fix CVE-2013-2338, upgrade the firmware of HP Integrated Lights-Out 3 to version 1.57 or later, or HP Integrated Lights-Out 4 to version 1.22 or later.
CVE-2013-2338 affects HP Integrated Lights-Out 3 and 4 cards with specific firmware versions prior to the latest updates.
Yes, CVE-2013-2338 can potentially be exploited by remote attackers without requiring authentication if Single-Sign-On is enabled.
Disabling Single-Sign-On on affected HP Integrated Lights-Out cards may reduce the risk of exploitation while waiting for firmware updates.