First published: Tue Dec 19 2023(Updated: )
A potential security vulnerability has been identified in HPE Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 6 (iLO 6). The vulnerability could be remotely exploited to allow authentication bypass.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
HP Integrated Lights-Out 5 | >=2.63<=3.00 | |
HP Integrated Lights-Out 5 firmware | ||
All of | ||
HPE Integrated Lights-Out 6 | >=1.05<=1.55 | |
HPE Integrated Lights-Out 6 firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-50272 has been rated as a high severity vulnerability due to the potential for authentication bypass.
To fix CVE-2023-50272, upgrade the HPE Integrated Lights-Out firmware to a version higher than 3.00 for iLO 5 or higher than 1.55 for iLO 6.
Yes, CVE-2023-50272 can be remotely exploited, allowing attackers to bypass authentication.
CVE-2023-50272 affects HPE Integrated Lights-Out 5 firmware versions between 2.63 and 3.00 and iLO 6 firmware versions between 1.05 and 1.55.
Systems running affected versions of HPE Integrated Lights-Out 5 and iLO 6 are at risk due to CVE-2023-50272.