HPE Alert
3334Warning Date
Severity Level
Warning Number
Target Sector
12 April, 2022
● Medium
2022-4649
All
HPE has released a security update to address several vulnerabilities in the following products:
- HPE Integrated Lights-Out 4 (iLO 4) - Prior to version 2.80
- HPE Apollo 4200 Gen9 Server - Prior to iLO 4 version 2.80
- HPE ProLiant BL460c Gen9 Server Blade - Prior to iLO 4 version 2.80
- HPE ProLiant BL660c Gen9 Server - Prior to iLO 4 version 2.80
- HPE ProLiant DL120 Gen9 Server - Prior to iLO 4 version 2.80
- HPE ProLiant DL160 Gen9 Server - Prior to iLO 4 version 2.80
- HPE ProLiant DL180 Gen9 Server - Prior to iLO 4 version 2.80
- HPE ProLiant DL20 Gen9 Server - Prior to iLO 4 version 2.80
- HPE ProLiant DL360 Gen9 Server - Prior to iLO 4 version 2.80
- HPE ProLiant DL380 Gen9 Server - Prior to iLO 4 version 2.80
- HPE ProLiant DL560 Gen9 Server - Prior to iLO 4 version 2.80
- HPE ProLiant DL580 Gen9 Server - Prior to iLO 4 version 2.80
- HPE ProLiant DL60 Gen9 Server - Prior to iLO 4 version 2.80
- HPE ProLiant DL80 Gen9 Server - Prior to iLO 4 version 2.80
- HPE ProLiant ML110 Gen9 Server - Prior to iLO 4 version 2.80
- HPE ProLiant ML150 Gen9 Server - Prior to iLO 4 version 2.80
- HPE ProLiant ML30 Gen9 Server - Prior to iLO 4 version 2.80
- HPE ProLiant ML350 Gen9 Server - Prior to iLO 4 version 2.80
- HPE ProLiant XL170r Gen9 Server - Prior to iLO 4 version 2.80
- HPE ProLiant XL190r Gen9 Server - Prior to iLO 4 version 2.80
- HPE ProLiant XL230a Gen9 Server - Prior to iLO 4 version 2.80
- HPE ProLiant XL250a Gen9 Server - Prior to iLO 4 version 2.80
- HPE ProLiant XL450 Gen9 Server - Prior to iLO 4 version 2.80
- HPE ProLiant XL730f Gen9 Server - Prior to iLO 4 version 2.80
- HPE ProLiant XL740f Gen9 Server - Prior to iLO 4 version 2.80
- HPE ProLiant XL750f Gen9 Server - Prior to iLO 4 version 2.80
- HPE Synergy 480 Gen9 Compute Module - Prior to iLO 4 version 2.80
- HPE Synergy 620 Gen9 Compute Module - Prior to iLO 4 version 2.80
- HPE Synergy 660 Gen9 Compute Module - Prior to iLO 4 version 2.80
- HPE Synergy 680 Gen9 Compute Module - Prior to iLO 4 version 2.80
- HPE ProLiant WS460c Gen9 Graphics Server Blade - Prior to iLO 4 version 2.80
- HPE ProLiant WS460c Gen8 Graphics Server Blade - Prior to iLO 4 version 2.80
- HPE ProLiant MicroServer Gen8 - Prior to iLO 4 version 2.80
- HPE ProLiant SL210t Gen8 Server - Prior to iLO 4 version 2.80
- HPE ProLiant SL230s Gen8 Server - Prior to iLO 4 version 2.80
- HPE ProLiant SL250s Gen8 Server - Prior to iLO 4 version 2.80
- HPE ProLiant SL270s Gen8 SE Server - Prior to iLO 4 version 2.80
- HPE ProLiant SL270s Gen8 Server - Prior to iLO 4 version 2.80
- HPE ProLiant SL4540 Gen8 1 Node Server - Prior to iLO 4 version 2.80
- HPE ProLiant BL420c Gen8 Server - Prior to iLO 4 version 2.80
- HPE ProLiant BL460c Gen8 Server Blade - Prior to iLO 4 version 2.80
- HPE ProLiant BL465c Gen8 Server Blade - Prior to iLO 4 version 2.80
- HPE ProLiant BL660c Gen8 Server Blade - Prior to iLO 4 version 2.80
- HPE ProLiant DL320e Gen8 Server - Prior to iLO 4 version 2.80
- HPE ProLiant DL320e Gen8 v2 Server - Prior to iLO 4 version 2.80
- HPE ProLiant DL360e Gen8 Server - Prior to iLO 4 version 2.80
- HPE ProLiant DL360p Gen8 Server - Prior to iLO 4 version 2.80
- HPE ProLiant DL380e Gen8 Server - Prior to iLO 4 version 2.80
- HPE ProLiant DL380p Gen8 Server - Prior to iLO 4 version 2.80
- HPE ProLiant DL385p Gen8 (AMD) - Prior to iLO 4 version 2.80
- HPE ProLiant DL560 Gen8 Server - Prior to iLO 4 version 2.80
- HPE ProLiant DL580 Gen8 Server - Prior to iLO 4 version 2.80
- HPE ProLiant ML310e Gen8 Server - Prior to iLO 4 version 2.80
- HPE ProLiant ML310e Gen8 v2 Server - Prior to iLO 4 version 2.80
- HPE ProLiant ML350e Gen8 v2 Server - Prior to iLO 4 version 2.80
- HPE ProLiant ML350p Gen8 Server - Prior to iLO 4 version 2.80
- HPE ProLiant DL160 Gen8 Server - Prior to iLO 4 version 2.80
- HPE ProLiant XL220a Gen8 v2 Server - Prior to iLO 4 version 2.80
- HPE ProLiant EC200a Server - Prior to iLO 4 version 2.80
An attacker could exploit these vulnerabilities by doing the following:
- Denial of service attack (DoS)
The CERT team encourages users to review HPE security advisory and apply the necessary update: