First published: Tue Mar 31 2015(Updated: )
Unspecified vulnerability in HP Integrated Lights-Out (iLO) firmware 2 before 2.27, 3 before 1.82, and 4 before 2.10 allows remote attackers to bypass intended access restrictions or cause a denial of service via unknown vectors.
Credit: hp-security-alert@hp.com
Affected Software | Affected Version | How to fix |
---|---|---|
HP Integrated Lights-Out 2 | <=2.25 | |
HP Integrated Lights-Out 3 | <=1.80 | |
HP Integrated Lights-Out 4 mRCA firmware | <=2.03 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2106 is classified as a high-severity vulnerability due to its potential to allow remote access and denial of service.
To mitigate CVE-2015-2106, update your HP Integrated Lights-Out firmware to versions 2.27 or higher for iLO 2, 1.82 or higher for iLO 3, and 2.10 or higher for iLO 4.
CVE-2015-2106 affects HP Integrated Lights-Out firmware versions 2.25 and below for iLO 2, 1.80 and below for iLO 3, and 2.03 and below for iLO 4.
Exploitation of CVE-2015-2106 can lead to bypassing access restrictions or causing denial of service.
Currently, the recommended action for CVE-2015-2106 is to update the firmware as there are no known effective workarounds.