CVE-2013-2338
high · 10Unspecified vulnerability on HP Integrated Lights-Out 3 (aka iLO3) cards with firmware before 1.57 and 4 (aka iLO4) cards with firmware before 1.22, when Single-Sign-On (SSO) is used, allows remote attackers to execute arbitrary code via unknown vectors.
10
CVSS
10.4%
EPSS (exploit prob.)
96th
EPSS percentile
2013-06-14
Published
AV:N/AC:L/Au:N/C:C/I:C/A:C
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| hp | integrated_lights-out_3_firmware | <= 1.55 |
| hp | integrated_lights-out_3_firmware | 1.00 |
| hp | integrated_lights-out_3_firmware | 1.05 |
| hp | integrated_lights-out_3_firmware | 1.20 |
| hp | integrated_lights-out_3_firmware | 1.26 |
| hp | integrated_lights-out_3_firmware | 1.28 |
| hp | integrated_lights-out_3_firmware | 1.50 |
| hp | integrated_lights-out_4_firmware | <= 1.20 |
| hp | integrated_lights-out_4_firmware | 1.11 |
| hp | integrated_lights-out_4_firmware | 1.13 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2013-2338