Impact
A flaw in the HPE Integrated Lights-Out (iLO) 7 firmware allows a remote user to bypass validation checks, effectively gaining unauthorized access to management functions that should be protected by authentication. The weakness stems from an improper authentication process, enabling attackers to execute privileged operations without valid credentials. As a result, the confidentiality, integrity, and availability of the managed hardware could be compromised.
Affected Systems
The vulnerability affects Hewlett Packard Enterprise’s Integrated Lights-Out (iLO) version 7 firmware. No specific revision numbers are listed, so all iLO 7 deployments without the patch are potentially impacted.
Risk and Exploitability
The CVSS score of 9 indicates a high severity impact with network reachability. Although EPSS data is not available, the lack of a KEV listing does not mitigate the high risk profile. The attack vector is remote; an attacker only needs network access to the iLO interface and can exploit the validation failure without interacting with the host operating system. Given the critical nature of iLO management functions, the potential for full system compromise is significant.
OpenCVE Enrichment