Database/Control plane, storage & DevOps

HPE iLO3 / iLO4: Multiple unspecified flaws allowing remote information disclosure, data modification and DoS
CVSS 9.8CVE-2016-4375Control plane, storage & DevOpscurated
Impact
Multiple unspecified flaws allowing remote information disclosure, data modification and DoS on the management controller
Who can reach it
Network
What to do
iLO firmware update (iLO3 <1.88, iLO4 <2.44); the "unspecified" advisory style means operators cannot risk-assess individual issues and must patch blind
References
Related entries
- Tridium Niagara AX (<=3.8) and Niagara 4 (<=4.4) framework: Log into the Niagara platform with a disabled account nameCVE-2017-16748 · Tridium Niagara AX (<=3.8) and Niagara 4 (<=4.4) frameworkCritical
- Lenovo / IBM Integrated Management Module 2 (IMM2) web administration service: The overflow is inside theCVE-2017-3774 · Lenovo / IBM Integrated Management Module 2 (IMM2) web administration serviceCritical
- Intel Active Management Technology / Standard Manageability: An authentication bypass in the AMT web interface: sendingCVE-2017-5689 · Intel Active Management Technology / Standard ManageabilityCritical
- HPE iLO2: Authentication bypass and code execution in iLO2 firmware 2.29CVE-2017-8979 · HPE iLO2Critical
- ntpq / ntpdc (NTP 4.2.8p11 client utilities): Stack buffer overflow in the ntpq and ntpdc command-line tools via a longCVE-2018-12327 · ntpq / ntpdc (NTP 4.2.8p11 client utilities)Critical
- Ceph iSCSI gateway (ceph-iscsi-cli / rbd-target-api): rbd-target-api ships with the Werkzeug debug console enabledCVE-2018-14649 · Ceph iSCSI gateway (ceph-iscsi-cli / rbd-target-api)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.