Database/Control plane, storage & DevOps

HPE iLO2: Authentication bypass and code execution in iLO2 firmware 2.29
CVSS 9.8CVE-2017-8979Control plane, storage & DevOpscurated
Impact
Authentication bypass and code execution in iLO2 firmware 2.29
Who can reach it
Network, unauthenticated
What to do
iLO2 is EOL — remediation is decommissioning or hard network isolation, not patching
References
Related entries
- ntpq / ntpdc (NTP 4.2.8p11 client utilities): Stack buffer overflow in the ntpq and ntpdc command-line tools via a longCVE-2018-12327 · ntpq / ntpdc (NTP 4.2.8p11 client utilities)Critical
- Ceph iSCSI gateway (ceph-iscsi-cli / rbd-target-api): rbd-target-api ships with the Werkzeug debug console enabledCVE-2018-14649 · Ceph iSCSI gateway (ceph-iscsi-cli / rbd-target-api)Critical
- Raritan CommandCenter Secure Gateway (CC-SG), before 8.0.0: CC-SG is Raritan's single-pane-of-glass gateway thatCVE-2018-20687 · Raritan CommandCenter Secure Gateway (CC-SG), before 8.0.0Critical
- Slurm (slurmdbd accounting database daemon): SQL injection into SlurmDBD gives an attacker read and write control ofCVE-2018-7033 · Slurm (slurmdbd accounting database daemon)Critical
- Kemp LoadMaster (LMOS): A flaw in session management lets a remote, unauthenticated attacker bypass the LoadMaster'sCVE-2018-9091 · Kemp LoadMaster (LMOS)Critical
- Slurm (slurmdbd, sacctmgr archive load): A second SQL injection path into SlurmDBD, this one through the 'sacctmgrCVE-2019-12838 · Slurm (slurmdbd, sacctmgr archive load)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.