iLO 3 < 1.90 / iLO 4 < 2.61 / iLO 5 < 1.35 Remote Code Execution Vulnerability (HPESBHF03866)

High Nessus Plugin ID 134976

Synopsis

The remote HP Integrated Lights-Out (iLO) server's web interface is affected by a remote code execution vulnerability.

Description

A remote command execution vulnerability exists in HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers prior to v1.35, HPE Integrated Lights-Out 4 (iLO 4) prior to v2.61, HPE Integrated Lights-Out 3 (iLO 3) prior to v1.90 could be remotely exploited to execute arbitrary code leading to disclosure of information. An authenticated, remote attacker can exploit this to bypass authentication and execute arbitrary commands.

Solution

Upgrade firmware of For iLO 3, upgrade firmware to 1.90 or later. For iLO 4, upgrade firmware to 2.61 or later. For iLO 5, upgrade firmware to 1.35 or later.
Alternatively, apply the workarounds outlined in the vendor advisory.

See Also

http://www.nessus.org/u?27f0bcb2

Plugin Details

Severity: High

ID: 134976

File Name: ilo_HPESBHF_03866.nasl

Version: 1.2

Type: remote

Family: CGI abuses

Published: 2020/03/27

Updated: 2020/03/31

Dependencies: 20285

Risk Information

Risk Factor: High

CVSS Score Source: CVE-2018-7105

CVSS v2.0

Base Score: 9

Temporal Score: 6.7

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

CVSS v3.0

Base Score: 7.2

Temporal Score: 6.3

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:hp:integrated_lights-out_firmware

Required KB Items: www/ilo, ilo/generation, ilo/firmware

Exploit Ease: No known exploits are available

Patch Publication Date: 2017/08/06

Vulnerability Publication Date: 2018/09/13

Reference Information

CVE: CVE-2018-7105

BID: 105425