Database/Firmware, BMC & network fabric

HPE iLO 5 (local privilege escalation to code execution): An unprivileged user can execute arbitrary code in the iLO
Impact
An unprivileged user can execute arbitrary code in the iLO context. This is one of a batch of a dozen-plus iLO 5 defects HPE fixed in the same firmware release, which is itself the useful signal: the iLO 5 codebase had a cluster of memory-safety and access-control problems reachable without high privilege. Any one of them lands the attacker on the service processor, with the usual consequences - power, Virtual Media boot, console, and persistence below the hypervisor.
Who can reach it
An unprivileged actor with local access to the iLO's own execution environment - in practice, someone who already has a low-privilege iLO account or a foothold reached through one of the sibling defects in the same batch. Not an unauthenticated internet-facing entry point.
What to do
Flash iLO 5 to v2.71 or later - and note that the later CVE-2022-28639 batch requires v2.72, so go straight to the highest available iLO 5 build rather than patching to the floor. Out-of-band, per-node, no host reboot and no drain. Treat this as one flash covering a whole batch of CVEs, which makes the per-node rollout cost-effective.
References
Related entries
- Phoenix SecureCore Technology 4 (SMI handler, improper access control): An SMI handler with missing access control letsCVE-2023-31100 · Phoenix SecureCore Technology 4 (SMI handler, improper access control)High
- AMD Secure Processor - XGMI Trusted Agent (type confusion): Type confusion in the ASP's XGMI Trusted Agent means aCVE-2023-31323 · AMD Secure Processor - XGMI Trusted Agent (type confusion)High
- Dell SmartFabric OS10 (hard-coded password): A hard-coded password in OS10 10.5.6.x gives an unauthenticated attackerCVE-2024-48831 · Dell SmartFabric OS10 (hard-coded password)High
- Supermicro BMC firmware update signature/validation logic on the X13SEM-F motherboard family: The operator losesCVE-2025-12007 · Supermicro BMC firmware update signature/validation logic on the X13SEM-F motherboard familyHigh
- Junos OS: missing authentication in command processing gives a privileged local user root on line cardsCVE-2025-30650 · Juniper Junos OS (command processing on Linux-based line cards: MPC7-11, LC2101/480/9600, MX304, MX-SPC3, PTX FPC3)High
- IBM Power Systems Firmware: HMC-authenticated attacker executes code on the service processorCVE-2026-16832 · IBM Power Systems Firmware (FSP management network protocol)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.