First published: Thu Sep 08 2016(Updated: )
Multiple unspecified vulnerabilities in HPE Integrated Lights-Out 3 (aka iLO 3) firmware before 1.88, Integrated Lights-Out 4 (aka iLO 4) firmware before 2.44, and Integrated Lights-Out 4 (aka iLO 4) mRCA firmware before 2.32 allow remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HP Integrated Lights-Out 3 | =1.87 | |
HP Integrated Lights-Out 4 mRCA firmware | =2.43 | |
HP Integrated Lights-Out 4 mRCA firmware | =2.31 | |
HP Integrated Lights-Out 3 | ||
HP Integrated Lights-Out 4 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4375 has not been explicitly assigned a severity rating, but it allows remote attackers to obtain sensitive information and modify data.
To fix CVE-2016-4375, upgrade the HPE Integrated Lights-Out 3 firmware to version 1.88 or later, and the HPE Integrated Lights-Out 4 firmware to version 2.44 or later.
CVE-2016-4375 affects HPE Integrated Lights-Out 3 firmware versions prior to 1.88 and Integrated Lights-Out 4 firmware versions prior to 2.44 and 2.32.
CVE-2016-4375 does not specifically indicate remote code execution capabilities, but it does allow sensitive data access and modification.
There are no documented workarounds for CVE-2016-4375; updating to the patched firmware is necessary to mitigate the vulnerability.