CVE-2023-50272: Critical severity hp integrated lights-out 5 vulnerability
A potential security vulnerability has been identified in HPE Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 6 (iLO 6). The vulnerability could be remotely exploited to allow authentication bypass.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50272?
CVE-2023-50272 has been rated as a high severity vulnerability due to the potential for authentication bypass.
How do I fix CVE-2023-50272?
To fix CVE-2023-50272, upgrade the HPE Integrated Lights-Out firmware to a version higher than 3.00 for iLO 5 or higher than 1.55 for iLO 6.
Can CVE-2023-50272 be exploited remotely?
Yes, CVE-2023-50272 can be remotely exploited, allowing attackers to bypass authentication.
Which versions of HPE Integrated Lights-Out are affected by CVE-2023-50272?
CVE-2023-50272 affects HPE Integrated Lights-Out 5 firmware versions between 2.63 and 3.00 and iLO 6 firmware versions between 1.05 and 1.55.
What systems are at risk due to CVE-2023-50272?
Systems running affected versions of HPE Integrated Lights-Out 5 and iLO 6 are at risk due to CVE-2023-50272.