First published: Sat Aug 03 2013(Updated: )
Unspecified vulnerability in HP Integrated Lights-Out 3 (aka iLO3) firmware before 1.60 and 4 (aka iLO4) firmware before 1.30 allows remote attackers to bypass authentication via unknown vectors.
Credit: hp-security-alert@hp.com
Affected Software | Affected Version | How to fix |
---|---|---|
HP Integrated Lights-Out Firmware | <=1.51a | |
HP Integrated Lights-Out Firmware | =1.10 | |
HP Integrated Lights-Out Firmware | =1.15 | |
HP Integrated Lights-Out Firmware | =1.15a | |
HP Integrated Lights-Out Firmware | =1.16a | |
HP Integrated Lights-Out Firmware | =1.20a | |
HP Integrated Lights-Out Firmware | =1.26a | |
HP Integrated Lights-Out Firmware | =1.27a | |
HP Integrated Lights-Out Firmware | =1.40a | |
HP Integrated Lights-Out Firmware | =1.41a | |
HP Integrated Lights-Out Firmware | =1.42a | |
HP Integrated Lights-Out Firmware | =1.50 | |
HP Integrated Lights-Out Firmware | =1.50a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4805 is rated as a high severity vulnerability due to its potential for remote authentication bypass.
To fix CVE-2013-4805, upgrade to HP Integrated Lights-Out firmware version 1.60 or later for iLO3 and 1.30 or later for iLO4.
CVE-2013-4805 affects HP Integrated Lights-Out firmware versions prior to 1.60 for iLO3 and versions prior to 1.30 for iLO4.
Yes, CVE-2013-4805 can potentially allow unauthorized remote access, which may lead to data breaches.
Yes, remote authentication bypass vulnerabilities like CVE-2013-4805 are not uncommon and can significantly increase security risks.