HP Integrated Lights-Out Denial of Service (CVE-2004-0525)

medium Tenable OT Security Plugin ID 504411

Synopsis

The remote OT asset is affected by a vulnerability.

Description

HP Integrated Lights-Out (iLO) 1.10 and other versions before 1.55 allows remote attackers to cause a denial of service (hang) by accessing iLO using the TCP/IP reserved port zero.

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

Refer to the vendor advisory.

See Also

http://seclists.org/lists/bugtraq/2004/May/0281.html

http://www.securityfocus.com/bid/10415

https://exchange.xforce.ibmcloud.com/vulnerabilities/16251

Plugin Details

Severity: Medium

ID: 504411

Version: 1.1

Type: remote

Family: Tenable.ot

Published: 11/13/2025

Updated: 11/13/2025

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2004-0525

Vulnerability Information

CPE: cpe:/o:hp:integrated_lights-out_firmware:1.27a, cpe:/o:hp:integrated_lights-out_firmware:1.10, cpe:/o:hp:integrated_lights-out_firmware:1.50a, cpe:/o:hp:integrated_lights-out_firmware:1.20a, cpe:/o:hp:integrated_lights-out_firmware:1.16a, cpe:/o:hp:integrated_lights-out_firmware:1.41a, cpe:/o:hp:integrated_lights-out_firmware:1.26a, cpe:/o:hp:integrated_lights-out_firmware:1.51a, cpe:/o:hp:integrated_lights-out_firmware:1.6a, cpe:/o:hp:integrated_lights-out_firmware:1.15a, cpe:/o:hp:integrated_lights-out_firmware:1.50, cpe:/o:hp:integrated_lights-out_firmware:1.42a, cpe:/o:hp:integrated_lights-out_firmware:1.15, cpe:/o:hp:integrated_lights-out_firmware:1.40a

Required KB Items: Tenable.ot/HP

Exploit Ease: No known exploits are available

Patch Publication Date: 8/6/2004

Vulnerability Publication Date: 8/6/2004

Reference Information

CVE: CVE-2004-0525