Lucene search

K
cveHpeCVE-2021-46846
HistoryDec 12, 2022 - 1:15 p.m.

CVE-2021-46846

2022-12-1213:15:11
CWE-79
hpe
web.nvd.nist.gov
34
cve
2021
46846
cross site scripting
hpe
ilo 5
vulnerability

CVSS3

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:L

EPSS

0.001

Percentile

23.8%

Cross Site Scripting vulnerability in Hewlett Packard Enterprise Integrated Lights-Out 5.

Affected configurations

Nvd
Node
hp3par_service_processorMatch-
OR
hpapollo_r2000_chassisMatch-
OR
hpeapollo_2000_gen10_plus_systemMatch-
OR
hpeapollo_4200_gen10_serverMatch-
OR
hpeapollo_4510_gen10_systemMatch-
OR
hpeapollo_6500_gen10_plus_systemMatch-
OR
hpeintegrated_lights-out_5Match-
OR
hpeproliant_bl460c_gen10_server_bladeMatch-
OR
hpeproliant_dl120_gen10_serverMatch-
OR
hpeproliant_dl160_gen10_serverMatch-
OR
hpeproliant_dl180_gen10_serverMatch-
OR
hpeproliant_dl20_gen10_serverMatch-
OR
hpeproliant_dl325_gen10_plus_serverMatch-
OR
hpeproliant_dl325_gen10_serverMatch-
OR
hpeproliant_dl360_gen10_serverMatch-
OR
hpeproliant_dl380_gen10_serverMatch-
OR
hpeproliant_dl385_gen10_plus_serverMatch-
OR
hpeproliant_dl385_gen10_serverMatch-
OR
hpeproliant_dl560_gen10_serverMatch-
OR
hpeproliant_dl580_gen10_serverMatch-
OR
hpeproliant_dx385_gen10_plus_serverMatch-
OR
hpeproliant_e910_server_bladeMatch-
OR
hpeproliant_e910t_server_bladeMatch-
OR
hpeproliant_m750_server_bladeMatch-
OR
hpeproliant_microserver_gen10Match-
OR
hpeproliant_microserver_gen10_plusMatch-
OR
hpeproliant_ml110_gen10_serverMatch-
OR
hpeproliant_ml30_gen10_serverMatch-
OR
hpeproliant_ml350_gen10_serverMatch-
OR
hpeproliant_xl170r_gen10_serverMatch-
OR
hpeproliant_xl190r_gen10_serverMatch-
OR
hpeproliant_xl220n_gen10_plus_serverMatch-
OR
hpeproliant_xl230k_gen10_serverMatch-
OR
hpeproliant_xl270d_gen10_serverMatch-
OR
hpeproliant_xl290n_gen10_plus_serverMatch-
OR
hpeproliant_xl450_gen10_serverMatch-
OR
hpeproliant_xl645d_gen10_plus_serverMatch-
OR
hpeproliant_xl675d_gen10_plus_serverMatch-
OR
hpestorage_file_controllerMatch-
OR
hpestoreeasy_1460_storageMatch-
OR
hpestoreeasy_1560_storageMatch-
OR
hpestoreeasy_1660_expanded_storageMatch-
OR
hpestoreeasy_1660_storageMatch-
OR
hpestoreeasy_1860_storageMatch-
AND
hpintegrated_lights-out_5_firmwareRange<2.44
VendorProductVersionCPE
hp3par_service_processor-cpe:2.3:h:hp:3par_service_processor:-:*:*:*:*:*:*:*
hpapollo_r2000_chassis-cpe:2.3:h:hp:apollo_r2000_chassis:-:*:*:*:*:*:*:*
hpeapollo_2000_gen10_plus_system-cpe:2.3:h:hpe:apollo_2000_gen10_plus_system:-:*:*:*:*:*:*:*
hpeapollo_4200_gen10_server-cpe:2.3:h:hpe:apollo_4200_gen10_server:-:*:*:*:*:*:*:*
hpeapollo_4510_gen10_system-cpe:2.3:h:hpe:apollo_4510_gen10_system:-:*:*:*:*:*:*:*
hpeapollo_6500_gen10_plus_system-cpe:2.3:h:hpe:apollo_6500_gen10_plus_system:-:*:*:*:*:*:*:*
hpeintegrated_lights-out_5-cpe:2.3:h:hpe:integrated_lights-out_5:-:*:*:*:*:*:*:*
hpeproliant_bl460c_gen10_server_blade-cpe:2.3:h:hpe:proliant_bl460c_gen10_server_blade:-:*:*:*:*:*:*:*
hpeproliant_dl120_gen10_server-cpe:2.3:h:hpe:proliant_dl120_gen10_server:-:*:*:*:*:*:*:*
hpeproliant_dl160_gen10_server-cpe:2.3:h:hpe:proliant_dl160_gen10_server:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 451

CNA Affected

[
  {
    "defaultStatus": "affected",
    "product": "HPE Integrated Lights-Out 5",
    "vendor": "Hewlett Packard Enterprise (HPE)",
    "versions": [
      {
        "status": "affected",
        "version": "Prior to 2.44"
      }
    ]
  }
]

CVSS3

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:L

EPSS

0.001

Percentile

23.8%

Related for CVE-2021-46846