Database/Firmware, BMC & network fabric

HPE iLO 5 / iLO 6 (authentication bypass): Authentication bypass on the iLO itself, remotely, with no credentials
Impact
Authentication bypass on the iLO itself, remotely, with no credentials. That is the whole out-of-band plane on a ProLiant or Apollo node: power control, Virtual Media to boot an attacker-supplied image, remote console into the tenant's session, and a firmware-level foothold that persists through host reimaging. The CVSS vector marks scope as changed, which reflects exactly that - getting the BMC gets you more than the BMC. Affects iLO 5 from v2.63 up to (not including) v3.00, and iLO 6 from v1.05 up to v1.55, so it spans both the Gen10/Gen10 Plus and Gen11 fleets.
Who can reach it
Anything routable to the iLO address on the out-of-band management VLAN, unauthenticated. Attack complexity is rated high, so it is not a trivial one-shot, but it requires no account and no host access - the exposure is defined purely by who can reach the iLO.
What to do
Flash iLO 5 to v3.00 or later, iLO 6 to v1.55 or later. Out-of-band, per-node, via the iLO web UI, iLOrest, Redfish or OneView - no host reboot and no drain of running jobs; the iLO resets itself and OOB access is unavailable for a couple of minutes. Interim config-only control: restrict the iLO management network to an explicit allowlist of jump hosts, since there is no per-feature toggle that closes an authentication bypass.
References
Related entries
- Linux kernel (drivers/infiniband/sw/siw): When soft-iWARP fails to process an inbound MPA connection requestCVE-2023-52513 · Linux kernel (drivers/infiniband/sw/siw)High
- Phoenix SecureCore (TPM configuration / SetupUtility, unsafe UEFI variable handling in SMM): A buffer overflow in howCVE-2024-0762 · Phoenix SecureCore (TPM configuration / SetupUtility, unsafe UEFI variable handling in SMM)High
- Brocade Fabric OS (firmware download credential capture): Fabric OS captures the SFTP/FTP server password usedCVE-2024-10403 · Brocade Fabric OS (firmware download credential capture)High
- Juniper Junos OS Packet Forwarding Engine (VXLAN + ICMP): A high rate of specific ICMP traffic to a device with VXLANCVE-2024-21595 · Juniper Junos OS Packet Forwarding Engine (VXLAN + ICMP)High
- IBM OpenBMC bmcweb HTTPS server (FW1050.00 - FW1050.10): Certain URIs on IBM's OpenBMC-derived bmcweb returnCVE-2024-31916 · IBM OpenBMC bmcweb HTTPS server (FW1050.00 - FW1050.10)High
- IBM OpenBMC default password and session management (FW1020, FW1030, FW1050): The combination of a shipped defaultCVE-2024-35124 · IBM OpenBMC default password and session management (FW1020, FW1030, FW1050)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.