Database/Firmware, BMC & network fabric

HPE iLO 4 / iLO 5 (unauthenticated information disclosure): An unauthenticated remote request pulls back the server
Impact
An unauthenticated remote request pulls back the server serial number and other identifying detail from the iLO. Low impact on its own, high value as reconnaissance: it lets an attacker who can reach a management network enumerate exactly what hardware sits behind each iLO address, fingerprint generations, and pick which nodes are worth a real exploit - all without a single failed login to show up in an audit log. Covers ProLiant, Apollo, Synergy compute modules and Converged Systems, which is most of the HPE fleet shape a GPU operator would run.
Who can reach it
Anything routable to the iLO on the out-of-band management VLAN, unauthenticated. If any iLO is inadvertently internet-exposed, this is what a mass scanner harvests first.
What to do
Flash iLO 5 to v2.31 or later and iLO 4 to v2.76 or later. Out-of-band, per-node, no host reboot and no drain. Given the low direct impact, most operators should fold this into the next scheduled iLO firmware campaign rather than running a dedicated one - but do treat any internet-reachable iLO as an emergency independent of this CVE.
References
Related entries
- APC/Schneider Electric UPS, PDU, and cooling products using NMC2/NMC3 (Smart-UPS, Symmetra, Galaxy, rack PDUs, InRowCVE-2021-22815 · APC/Schneider Electric UPS, PDU, and cooling products using NMC2/NMC3Medium
- AMI MegaRAC SPx 12 / SPx 13 (BMC login): The login flow answers differently for real and fake usernames, soCVE-2021-45925 · AMI MegaRAC SPx 12 / SPx 13 (BMC login)Medium
- AMI MegaRAC: Weak MD5 password hashing for BMC accountsCVE-2022-40258 · AMI MegaRACMedium
- AMD IOMMU - nested page table entry faults bypass SEV-SNP RMP checks: The IOMMU mishandles invalid nested page tableCVE-2023-20582 · AMD IOMMU - nested page table entry faults bypass SEV-SNP RMP checksMedium
- AMD IOMMU - invalid device table entries bypass SEV-SNP RMP checks: The IOMMU mishandles certain special address rangesCVE-2023-20584 · AMD IOMMU - invalid device table entries bypass SEV-SNP RMP checksMedium
- AMI MegaRAC SPX (Redfish): User enumeration through RedfishCVE-2023-25192 · AMI MegaRAC SPX (Redfish)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.