You Can Bypass Authentication on HPE iLO4 Servers With 29 "A" Characters

You Can Bypass Authentication on HPE iLO4 Servers With 29 "A" Characters

5 years ago
Anonymous $cyhBy-qkd5

https://www.bleepingcomputer.com/news/security/you-can-bypass-authentication-on-hpe-ilo4-servers-with-29-a-characters/

Details and public exploit code have been published online for a severe vulnerability affecting Hewlett Packard Integrated Lights-Out 4 (HP iLO 4) servers.

HP iLO devices are extremely popular among small and large enterprises alike. iLO cards can be embedded in regular computers. They have a separate Ethernet network connection and run a proprietary embedded server management technology that provides out-of-band management features, allowing sysadmins to manage computers from afar.