Loading...
Loading...
On any HPE system with HPE Integrated Lights-Out 7 (iLO 7), the following is observed:HPE iLO7 SNMP v1 will work even if the user disables it from iLO GUI or Redfish interfaceAlso, SNMP v1 works with any community string, even if you update the community string in iLO 7 configuration settings.SNMP v1 is inherently insecure (plaintext authentication, easily guessable community strings).If SNMP is accepting any community string or still works when "disabled," your system is vulnerable and likely non-compliant with best security practices. This can be exposed to security issues.Additionally, SNMP walk requests are successful with any community string.
All HPE Gen12 servers with iLO 7 v1.19 and older versions.
Immediately restrict SNMP access, and ensure SNMP is truly disabled if not in use.ORuse SNMP v3 (with authentication and encryption).This is targeted to be resolved in a future iLO 7 firmware and this advisory wil be updated when this is available.
Operating Systems Affected:Not Applicable
Click on a version to see all relevant bugs
Hewlett Packard Enterprise Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.