Database/Control plane, storage & DevOps

HPE OneView (clusterService authentication bypass to DoS): Authentication bypass against the OneView cluster service
CVSS 7.5CVE-2023-50275Control plane, storage & DevOpscurated
Impact
Authentication bypass against the OneView cluster service causing denial of service - loss of the management plane for the HPE estate.
Who can reach it
Unauthenticated network access to the OneView appliance.
What to do
Apply the OneView update per HPESBGN04586.
References
Related entries
- CyberPower PowerPanel Business 4.11.0 - Service Watchdog on TCP/2003: An unauthenticated attacker can repeatedlyCVE-2024-11322 · CyberPower PowerPanel Business 4.11.0 - Service Watchdog on TCP/2003High
- OpenVPN: The interactive service pipe is reachable remotelyCVE-2024-24974 · OpenVPNHigh
- Intel Neural Compressor: Unauthenticated input-validation failure leading to escalation of privilege in NeuralCVE-2024-28028 · Intel Neural CompressorHigh
- Brocade SANnav OVA appliance image, before v2.3.1 and v2.3.0a: Three defects that together mean every SANnav OVACVE-2024-29966 · Brocade SANnav OVA appliance image, before v2.3.1 and v2.3.0aHigh
- AMD - DIMM SPD address aliasing bypassing SMM isolation (AMD-SB-3014): The BadRAM SPD-aliasing technique aimed atCVE-2024-36354 · AMD - DIMM SPD address aliasing bypassing SMM isolation (AMD-SB-3014)High
- Ceph RADOS Gateway (RGW): One malformed PUT kills the radosgw process. Sending an object copy with an emptyCVE-2024-47866 · Ceph RADOS Gateway (RGW)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.