HP Integrated Lights-Out信息泄露漏洞
发布日期:2012-11-21
更新日期:2012-11-23
受影响系统:
HP Integrated Lights Out 3 (iLO 3) 1.x
HP Integrated Lights Out 4 (iLO 4) 1.x
描述:
--------------------------------------------------------------------------------
CVE ID: CVE-2012-3271
HP Integrated Lights-Out是惠普内嵌式服务器管理技术,类似于其他厂商的Lights out management (LOM)技术。
HP Integrated Lights-Out 3 (iLO3) 1.28 及之前版本、HP Integrated Lights-Out 4 (iLO4) 1.11及之前版本在实现上存在安全漏洞,可导致获取管理员访问权限,泄露某些敏感信息。细节目前未知。
<*来源:vendor
链接:http://secunia.com/advisories/51378/
https://h20566.www2.hp.com/portal/site/hpsc/public/kb/ docDisplay?docId=emr_na-c03515413
*>
建议:
--------------------------------------------------------------------------------
厂商补丁:
HP
--
HP已经为此发布了一个安全公告(HPSBHF02821)以及相应补丁:
HPSBHF02821:SSRT100934 rev.1 - HP Integrated Lights-Out iLO3 and iLO4, Remote Disclosure of Information
链接:https://h20566.www2.hp.com/portal/site/hpsc/public/kb/ docDisplay?docId=emr_na-c03515413