A potential security vulnerability has been identified in HPE Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 4 (iLO 4) firmware. The vulnerability could be remotely exploited to disclose the serial number and other information.
Metrics
No CVSS v4.0
Attack Vector Network
Attack Complexity Low
Privileges Required None
Scope Unchanged
Confidentiality Impact Low
Integrity Impact None
Availability Impact None
User Interaction None
No CVSS v3.0
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact Partial
Integrity Impact None
Availability Impact None
This CVE is not in the KEV list.
The EPSS score is 0.00349.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
| Vendors | Products |
|---|---|
|
Hp
Subscribe
|
Apollo 4200 Gen10 Server
Subscribe
Apollo 4200 Gen9 Server
Subscribe
Apollo 4510 System
Subscribe
Apollo R2000 Chassis
Subscribe
Convergedsystem Cs700
Subscribe
Convergedsystem Cs700x
Subscribe
Integrated Lights-out 4
Subscribe
Integrated Lights-out 5
Subscribe
Proliant Bl420c Gen8 Server
Subscribe
Proliant Bl460c Gen10 Server Blade
Subscribe
Proliant Bl460c Gen8 Server Blade
Subscribe
Proliant Bl460c Gen9 Server Blade
Subscribe
Proliant Bl465c Gen8 Server Blade
Subscribe
Proliant Bl660c Gen8 Server Blade
Subscribe
Proliant Bl660c Gen9 Server
Subscribe
Proliant Dl120 Gen10 Server
Subscribe
Proliant Dl120 Gen9 Server
Subscribe
Proliant Dl160 Gen10 Server
Subscribe
Proliant Dl160 Gen8 Server
Subscribe
Proliant Dl160 Gen9 Server
Subscribe
Proliant Dl180 Gen10 Server
Subscribe
Proliant Dl180 Gen9 Server
Subscribe
Proliant Dl20 Gen10 Server
Subscribe
Proliant Dl320e Gen8 Server
Subscribe
Proliant Dl320e Gen8 V2 Server
Subscribe
Proliant Dl325 Gen10 Plus Server
Subscribe
Proliant Dl325 Gen10 Server
Subscribe
Proliant Dl360 Gen10 Server
Subscribe
Proliant Dl360 Gen9 Server
Subscribe
Proliant Dl360e Gen8 Server
Subscribe
Proliant Dl360p Gen8 Server
Subscribe
Proliant Dl380 Gen10 Server
Subscribe
Proliant Dl380 Gen9 Server
Subscribe
Proliant Dl380e Gen8 Server
Subscribe
Proliant Dl380p Gen8 Server
Subscribe
Proliant Dl385 Gen10 Plus Server
Subscribe
Proliant Dl385 Gen10 Server
Subscribe
Proliant Dl385p Gen8 \(amd\)
Subscribe
Proliant Dl560 Gen10 Server
Subscribe
Proliant Dl560 Gen8 Server
Subscribe
Proliant Dl560 Gen9 Server
Subscribe
Proliant Dl580 Gen10 Server
Subscribe
Proliant Dl580 Gen8 Server
Subscribe
Proliant Dl580 Gen9 Server
Subscribe
Proliant Dl60 Gen9 Server
Subscribe
Proliant Dl80 Gen9 Server
Subscribe
Proliant Microserver Gen8
Subscribe
Proliant Ml110 Gen10 Server
Subscribe
Proliant Ml110 Gen9 Server
Subscribe
Proliant Ml30 Gen10 Server
Subscribe
Proliant Ml30 Gen9 Server
Subscribe
Proliant Ml310e Gen8 Server
Subscribe
Proliant Ml310e Gen8 V2 Server
Subscribe
Proliant Ml350 Gen10 Server
Subscribe
Proliant Ml350 Gen9 Server
Subscribe
Proliant Ml350e Gen8 Server
Subscribe
Proliant Ml350e Gen8 V2 Server
Subscribe
Proliant Ml350p Gen8 Server
Subscribe
Proliant Sl210t Gen8 Server
Subscribe
Proliant Sl230s Gen8 Server
Subscribe
Proliant Sl250s Gen8 Server
Subscribe
Proliant Sl270s Gen8 Se Server
Subscribe
Proliant Sl270s Gen8 Server
Subscribe
Proliant Sl4540 Gen8 3 Node Server
Subscribe
Proliant Ws460c Gen8 Graphics Server Blade
Subscribe
Proliant Ws460c Gen9 Graphics Server Blade
Subscribe
Proliant Xl170r Gen10 Server
Subscribe
Proliant Xl170r Gen9 Server
Subscribe
Proliant Xl190r Gen10 Server
Subscribe
Proliant Xl190r Gen9 Server
Subscribe
Proliant Xl220a Gen8 V2 Server
Subscribe
Proliant Xl230a Gen9 Server
Subscribe
Proliant Xl230k Gen10 Server
Subscribe
Proliant Xl250a Gen9 Server
Subscribe
Proliant Xl270d Gen10 Server
Subscribe
Proliant Xl450 Gen10 Server
Subscribe
Proliant Xl450 Gen9 Server
Subscribe
Proliant Xl730f Gen9 Server
Subscribe
Proliant Xl740f Gen9 Server
Subscribe
Proliant Xl750f Gen9 Server
Subscribe
Synergy 480 Gen10 Compute Module
Subscribe
Synergy 480 Gen9 Compute Module
Subscribe
Synergy 660 Gen10 Compute Module
Subscribe
|
Configuration 1 [-]
| AND |
|
Configuration 2 [-]
| AND |
|
No data.
No data.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-28336 | A potential security vulnerability has been identified in HPE Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 4 (iLO 4) firmware. The vulnerability could be remotely exploited to disclose the serial number and other information. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: hpe
Published:
Updated: 2024-08-04T09:25:48.181Z
Reserved: 2020-01-16T00:00:00
Link: CVE-2020-7202
No data.
Status : Modified
Published: 2021-01-05T15:15:14.077
Modified: 2024-11-21T05:36:49.233
Link: CVE-2020-7202
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD