First published: Thu Apr 24 2014(Updated: )
The server in HP Integrated Lights-Out 2 (aka iLO 2) 2.23 and earlier allows remote attackers to cause a denial of service via crafted HTTPS traffic, as demonstrated by traffic from a CVE-2014-0160 vulnerability-assessment tool.
Credit: hp-security-alert@hp.com
Affected Software | Affected Version | How to fix |
---|---|---|
HP Integrated Lights-Out 2 | <=2.23 | |
HP Integrated Lights-Out 2 | =1.00 | |
HP Integrated Lights-Out 2 | =1.10 | |
HP Integrated Lights-Out 2 | =1.20 | |
HP Integrated Lights-Out 2 | =1.30 | |
HP Integrated Lights-Out 2 | =1.70 | |
HP Integrated Lights-Out 2 | =1.75 | |
HP Integrated Lights-Out 2 | =2.12 | |
HP Integrated Lights-Out 2 | =2.15 | |
HP Integrated Lights-Out 2 | =2.20 | |
HP Integrated Lights-Out 2 | =2.22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2601 is classified as a denial of service vulnerability, which can impact the availability of affected systems.
To mitigate CVE-2014-2601, upgrade the HP Integrated Lights-Out 2 firmware to version 2.23 or later.
CVE-2014-2601 affects HP Integrated Lights-Out 2 firmware versions prior to 2.23.
Yes, CVE-2014-2601 can be exploited by remote attackers through crafted HTTPS traffic.
Exploitation of CVE-2014-2601 can lead to a denial of service, disrupting access to the HP Integrated Lights-Out 2 management interface.