First published: Mon Jul 08 2013(Updated: )
The HP Integrated Lights-Out (iLO) BMC implementation allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher suite 0 (aka cipher zero) and an arbitrary password.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HP Integrated Lights-Out |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4784 is considered a high-severity vulnerability due to its ability to allow remote attackers to bypass authentication.
To fix CVE-2013-4784, update the HP Integrated Lights-Out firmware to the latest version provided by HP.
CVE-2013-4784 exploits the use of cipher suite 0 in the HP Integrated Lights-Out BMC, allowing unauthorized access.
CVE-2013-4784 affects users of HP Integrated Lights-Out BMC implementations that are using vulnerable cipher configurations.
Yes, CVE-2013-4784 can be mitigated by disabling the use of cipher suite 0 and enforcing stronger authentication protocols.