Lucene search

K
cve[email protected]CVE-2020-7202
HistoryJan 05, 2021 - 3:15 p.m.

CVE-2020-7202

2021-01-0515:15:14
web.nvd.nist.gov
33
2
cve-2020-7202
hpe
ilo 4
ilo 5
firmware
vulnerability
remote disclosure
security

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

5.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

39.4%

A potential security vulnerability has been identified in HPE Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 4 (iLO 4) firmware. The vulnerability could be remotely exploited to disclose the serial number and other information.

Affected configurations

NVD
Node
hpapollo_4200_gen9_serverMatch-
OR
hpconvergedsystem_cs700Match-
OR
hpconvergedsystem_cs700xMatch-
OR
hpproliant_bl420c_gen8_serverMatch-
OR
hpproliant_bl460c_gen8_server_bladeMatch-
OR
hpproliant_bl460c_gen9_server_bladeMatch-
OR
hpproliant_bl465c_gen8_server_bladeMatch-
OR
hpproliant_bl660c_gen8_server_bladeMatch-
OR
hpproliant_bl660c_gen9_serverMatch-
OR
hpproliant_dl120_gen9_serverMatch-
OR
hpproliant_dl160_gen8_serverMatch-
OR
hpproliant_dl160_gen9_serverMatch-
OR
hpproliant_dl180_gen9_serverMatch-
OR
hpproliant_dl320e_gen8_serverMatch-
OR
hpproliant_dl320e_gen8_v2_serverMatch-
OR
hpproliant_dl360_gen9_serverMatch-
OR
hpproliant_dl360e_gen8_serverMatch-
OR
hpproliant_dl360p_gen8_serverMatch-
OR
hpproliant_dl380_gen9_serverMatch-
OR
hpproliant_dl380e_gen8_serverMatch-
OR
hpproliant_dl380p_gen8_serverMatch-
OR
hpproliant_dl385p_gen8_\(amd\)Match-
OR
hpproliant_dl560_gen8_serverMatch-
OR
hpproliant_dl560_gen9_serverMatch-
OR
hpproliant_dl580_gen8_serverMatch-
OR
hpproliant_dl580_gen9_serverMatch-
OR
hpproliant_dl60_gen9_serverMatch-
OR
hpproliant_dl80_gen9_serverMatch-
OR
hpproliant_microserver_gen8Match-
OR
hpproliant_ml110_gen9_serverMatch-
OR
hpproliant_ml30_gen9_serverMatch-
OR
hpproliant_ml310e_gen8_serverMatch-
OR
hpproliant_ml310e_gen8_v2_serverMatch-
OR
hpproliant_ml350_gen9_serverMatch-
OR
hpproliant_ml350e_gen8_serverMatch-
OR
hpproliant_ml350e_gen8_v2_serverMatch-
OR
hpproliant_ml350p_gen8_serverMatch-
OR
hpproliant_sl210t_gen8_serverMatch-
OR
hpproliant_sl230s_gen8_serverMatch-
OR
hpproliant_sl250s_gen8_serverMatch-
OR
hpproliant_sl270s_gen8_se_serverMatch-
OR
hpproliant_sl270s_gen8_serverMatch-
OR
hpproliant_sl4540_gen8_3_node_serverMatch-
OR
hpproliant_ws460c_gen8_graphics_server_bladeMatch-
OR
hpproliant_ws460c_gen9_graphics_server_bladeMatch-
OR
hpproliant_xl170r_gen9_serverMatch-
OR
hpproliant_xl190r_gen9_serverMatch-
OR
hpproliant_xl220a_gen8_v2_serverMatch-
OR
hpproliant_xl230a_gen9_serverMatch-
OR
hpproliant_xl250a_gen9_serverMatch-
OR
hpproliant_xl450_gen9_serverMatch-
OR
hpproliant_xl730f_gen9_serverMatch-
OR
hpproliant_xl740f_gen9_serverMatch-
OR
hpproliant_xl750f_gen9_serverMatch-
OR
hpsynergy_480_gen9_compute_moduleMatch-
AND
hpintegrated_lights-out_4Range<2.76
Node
hpapollo_4200_gen10_serverMatch-
OR
hpapollo_4510_systemMatch-
OR
hpapollo_r2000_chassisMatch-
OR
hpconvergedsystem_cs700Match-
OR
hpconvergedsystem_cs700xMatch-
OR
hpproliant_bl460c_gen10_server_bladeMatch-
OR
hpproliant_dl120_gen10_serverMatch-
OR
hpproliant_dl160_gen10_serverMatch-
OR
hpproliant_dl180_gen10_serverMatch-
OR
hpproliant_dl20_gen10_serverMatch-
OR
hpproliant_dl325_gen10_plus_serverMatch-
OR
hpproliant_dl325_gen10_serverMatch-
OR
hpproliant_dl360_gen10_serverMatch-
OR
hpproliant_dl380_gen10_serverMatch-
OR
hpproliant_dl385_gen10_plus_serverMatch-
OR
hpproliant_dl385_gen10_serverMatch-
OR
hpproliant_dl560_gen10_serverMatch-
OR
hpproliant_dl580_gen10_serverMatch-
OR
hpproliant_ml110_gen10_serverMatch-
OR
hpproliant_ml30_gen10_serverMatch-
OR
hpproliant_ml350_gen10_serverMatch-
OR
hpproliant_xl170r_gen10_serverMatch-
OR
hpproliant_xl190r_gen10_serverMatch-
OR
hpproliant_xl230k_gen10_serverMatch-
OR
hpproliant_xl270d_gen10_serverMatch-
OR
hpproliant_xl450_gen10_serverMatch-
OR
hpsynergy_480_gen10_compute_moduleMatch-
OR
hpsynergy_660_gen10_compute_moduleMatch-
AND
hpintegrated_lights-out_5Range<2.31

CNA Affected

[
  {
    "product": "HPE ProLiant Servers, Apollo Products, Converged Systems, and Synergy Compute Modules with Integrated Lights-Out 5 (iLO 5), or Integrated Lights-Out 4 (iLO 4)",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Prior to iLO 5 v2.31"
      },
      {
        "status": "affected",
        "version": "Prior to iLO 4 v2.76"
      }
    ]
  }
]

Social References

More

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

5.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

39.4%

Related for CVE-2020-7202