Lucene search

K
cveHpeCVE-2017-12543
HistoryFeb 15, 2018 - 10:29 p.m.

CVE-2017-12543

2018-02-1522:29:04
CWE-200
hpe
web.nvd.nist.gov
32
information security
vulnerability
remote disclosure
moonshot remote console administrator
nvd

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.3

Confidence

High

EPSS

0.001

Percentile

40.3%

A remote disclosure of information vulnerability in Moonshot Remote Console Administrator Prior to 2.50, iLO4 prior to v2.53, iLO3 prior to v1.89 and iLO2 prior to v2.30 was found.

Affected configurations

Nvd
Node
hpmoonshot_remote_console_administratorRange<2.50
Node
hpintegrated_lights-out_2_firmwareRange<2.30
OR
hpintegrated_lights-out_3_firmwareRange<1.89
OR
hpintegrated_lights-out_4_firmwareRange<2.53
AND
hpintegrated_lights-outMatch-
VendorProductVersionCPE
hpmoonshot_remote_console_administrator*cpe:2.3:a:hp:moonshot_remote_console_administrator:*:*:*:*:*:*:*:*
hpintegrated_lights-out_2_firmware*cpe:2.3:o:hp:integrated_lights-out_2_firmware:*:*:*:*:*:*:*:*
hpintegrated_lights-out_3_firmware*cpe:2.3:o:hp:integrated_lights-out_3_firmware:*:*:*:*:*:*:*:*
hpintegrated_lights-out_4_firmware*cpe:2.3:o:hp:integrated_lights-out_4_firmware:*:*:*:*:*:*:*:*
hpintegrated_lights-out-cpe:2.3:h:hp:integrated_lights-out:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Integrated Lights-Out 4",
    "vendor": "Hewlett Packard Enterprise",
    "versions": [
      {
        "status": "affected",
        "version": "Moonshot Remote Console Administrator Prior to 2.50, iLO4 prior to v2.53, iLO3 prior to v1.89 and iLO2 prior to v2.30"
      }
    ]
  }
]

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.3

Confidence

High

EPSS

0.001

Percentile

40.3%

Related for CVE-2017-12543