CVE-2014-2601: High severity HP Integrated Lights-out 2 Firmware vulnerability
The server in HP Integrated Lights-Out 2 (aka iLO 2) 2.23 and earlier allows remote attackers to cause a denial of service via crafted HTTPS traffic, as demonstrated by traffic from a CVE-2014-0160 vulnerability-assessment tool.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2601?
CVE-2014-2601 is classified as a denial of service vulnerability, which can impact the availability of affected systems.
How do I fix CVE-2014-2601?
To mitigate CVE-2014-2601, upgrade the HP Integrated Lights-Out 2 firmware to version 2.23 or later.
What systems are affected by CVE-2014-2601?
CVE-2014-2601 affects HP Integrated Lights-Out 2 firmware versions prior to 2.23.
Can CVE-2014-2601 be exploited remotely?
Yes, CVE-2014-2601 can be exploited by remote attackers through crafted HTTPS traffic.
What impact does CVE-2014-2601 have on my network?
Exploitation of CVE-2014-2601 can lead to a denial of service, disrupting access to the HP Integrated Lights-Out 2 management interface.