CVE-2016-4379: Medium severity hp integrated lights-out 3 vulnerability
Published Sep 8, 2016
·Updated
The TLS implementation in HPE Integrated Lights-Out 3 (aka iLO3) firmware before 1.88 does not properly use a MAC protection mechanism in conjunction with CBC padding, which allows remote attackers to obtain sensitive information via a padding-oracle attack, aka a Vaudenay attack.
Affected Software
2 affected components
HP Integrated Lights-out 3 Firmware<=1.87
HP Integrated Lights-Out 3
Event History
Sep 8, 2016
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4379?
CVE-2016-4379 is categorized as a medium severity vulnerability.
2
How do I fix CVE-2016-4379?
To fix CVE-2016-4379, update the HPE Integrated Lights-Out 3 firmware to version 1.88 or later.
3
What devices are affected by CVE-2016-4379?
CVE-2016-4379 affects HPE Integrated Lights-Out 3 firmware versions prior to 1.88.
4
What type of attack is associated with CVE-2016-4379?
CVE-2016-4379 is associated with a padding-oracle attack, also known as a Vaudenay attack.
5
What information can be leaked due to CVE-2016-4379?
CVE-2016-4379 allows remote attackers to potentially obtain sensitive information through encryption vulnerabilities.