First published: Tue Mar 31 2015(Updated: )
Unspecified vulnerability in HP Integrated Lights-Out (iLO) firmware 2 before 2.27 and 4 before 2.03 and iLO Chassis Management (CM) firmware before 1.30 allows remote attackers to gain privileges, execute arbitrary code, or cause a denial of service via unknown vectors.
Credit: hp-security-alert@hp.com
Affected Software | Affected Version | How to fix |
---|---|---|
HP Integrated Lights-Out 2 | <=2.25 | |
HP Integrated Lights-Out 4 mRCA firmware | <=2.01 | |
HP Integrated Lights-Out Chassis Management firmware | <=1.29 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-7876 is considered a critical vulnerability due to its potential to allow remote attackers to gain privileges and execute arbitrary code.
To mitigate CVE-2014-7876, upgrade to HP Integrated Lights-Out firmware version 2.27 or later, and iLO Chassis Management firmware version 1.30 or later.
Vulnerable firmware versions include HP Integrated Lights-Out 2 before 2.27, HP Integrated Lights-Out 4 before 2.03, and iLO Chassis Management firmware before 1.30.
Yes, CVE-2014-7876 can be exploited by attackers to cause a denial of service.
Exploiting CVE-2014-7876 may allow attackers to gain privilege escalation and execute arbitrary code.