HP Integrated Lights-Out Denial of Service (CVE-2014-2601)

high Tenable OT Security Plugin ID 504426

Synopsis

The remote OT asset is affected by a vulnerability.

Description

The server in HP Integrated Lights-Out 2 (aka iLO 2) 2.23 and earlier allows remote attackers to cause a denial of service via crafted HTTPS traffic, as demonstrated by traffic from a CVE-2014-0160 vulnerability-assessment tool.

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

Refer to the vendor advisory.

See Also

http://www.nessus.org/u?d8ab84ef

http://www.securitytracker.com/id/1030148

http://www.nessus.org/u?805f8ab4

https://isc.sans.edu/forums/diary/Be+Careful+what+you+Scan+for/18017/

Plugin Details

Severity: High

ID: 504426

Version: 1.1

Type: remote

Family: Tenable.ot

Published: 11/13/2025

Updated: 11/13/2025

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: High

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2014-2601

Vulnerability Information

CPE: cpe:/o:hp:integrated_lights-out_2_firmware:1.00, cpe:/o:hp:integrated_lights-out_2_firmware:2.20, cpe:/o:hp:integrated_lights-out_2_firmware:1.75, cpe:/o:hp:integrated_lights-out_2_firmware:1.20, cpe:/o:hp:integrated_lights-out_2_firmware:2.15, cpe:/o:hp:integrated_lights-out_2_firmware, cpe:/o:hp:integrated_lights-out_2_firmware:2.12, cpe:/o:hp:integrated_lights-out_2_firmware:2.22, cpe:/o:hp:integrated_lights-out_2_firmware:1.70, cpe:/o:hp:integrated_lights-out_2_firmware:1.30, cpe:/o:hp:integrated_lights-out_2_firmware:1.10

Required KB Items: Tenable.ot/HP

Exploit Ease: No known exploits are available

Patch Publication Date: 4/24/2014

Vulnerability Publication Date: 4/24/2014

Reference Information

CVE: CVE-2014-2601