This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hewlett Packard Enterprise iLO Amplifier Pack. Authentication is not required to exploit this vulnerability. The specific flaw exists within the backup endpoint. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of root.
Affected Software | Affected Version | How to fix |
---|---|---|
Hewlett Packard Enterprise iLO Amplifier Pack |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
ZDI-CAN-14056 is considered a high severity vulnerability due to its potential to allow remote code execution without authentication.
To mitigate ZDI-CAN-14056, update the Hewlett Packard Enterprise iLO Amplifier Pack to the latest version as recommended by the vendor.
ZDI-CAN-14056 affects installations of Hewlett Packard Enterprise iLO Amplifier Pack.
Yes, ZDI-CAN-14056 can be exploited remotely without requiring authentication.
The potential impact of ZDI-CAN-14056 includes unauthorized remote code execution, which could compromise the affected system.