Database/Control plane, storage & DevOps

HPE iLO4: Authentication bypass and remote code execution — the "29 A's" `Connection` header bug
Impact
Authentication bypass and remote code execution — the "29 A's" Connection header bug; trivially scriptable pre-auth root on the BMC
Who can reach it
Network, unauthenticated
What to do
iLO4 firmware update to 2.53+; a node left unpatched here is fully owned by a single curl request
Fleet impact
How widespread
common - iLO is HPE's BMC across ProLiant/Apollo, incl. GPU-dense SKUs
Cost to remediate
firmware-flash to iLO >= 2.54 on every node, out-of-band; the exploit is trivial (a long header) and public, so exposure windows are measured in hours
Why it hits the whole fleet
Unauthenticated remote auth bypass into the BMC yields administrator on the management processor, virtual-media boot of attacker media, and firmware-level persistence under the OS - identical across every HPE node of that generation.
References
Related entries
- Cisco ACI Multi-Site Orchestrator (Application Services Engine): Complete unauthenticated authentication bypass on theCVE-2021-1388 · Cisco ACI Multi-Site Orchestrator (Application Services Engine)Critical
- GitLab: Image files passed unvalidated to a file parser (ExifTool)CVE-2021-22205 · GitLabCritical
- Eaton Intelligent Power Manager (IPM) prior to 1.69: Unauthenticated remote code execution on Eaton's power-managementCVE-2021-23281 · Eaton Intelligent Power Manager (IPM) prior to 1.69Critical
- Redis: Debian/Ubuntu packaging leaves a Lua sandbox escapeCVE-2022-0543 · RedisCritical
- Software House iSTAR Ultra door controller (before 6.8.9.CU01): Unauthenticated command injection giving rootCVE-2022-21941 · Software House iSTAR Ultra door controller (before 6.8.9.CU01)Critical
- HID Mercury intelligent controllers sold by Carrier LenelS2 (LNL-X2210/X2220/X3300/X4420/4420CVE-2022-31481 · HID Mercury intelligent controllers sold by Carrier LenelS2Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.