# N/A
## 概述
在HPE Integrated Lights-out 4 (iLO 4) 版本中发现了一个认证绕过和代码执行漏洞,影响了2.53版本之前的所有版本。
## 影响版本
- 所有低于2.53版本的HPE Integrated Lights-out 4 (iLO 4)
## 细节
攻击者可以利用此漏洞绕过认证并执行任意代码。
## 影响
此漏洞可能导致未授权访问和系统被恶意代码控制的风险。
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | Test and exploit for CVE-2017-12542 | https://github.com/skelsec/CVE-2017-12542 | POC详情 |
| 2 | Scan a list of given IP's for CVE-2017-12542 | https://github.com/sk1dish/ilo4-rce-vuln-scanner | POC详情 |
| 3 | HPE Integrated Lights-out 4 (iLO 4) prior to 2.53 was found to contain an authentication bypass and code execution vulnerability. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2017/CVE-2017-12542.yaml | POC详情 |
| 4 | This script checks if an HP iLO server is vulnerable and can add an admin user | https://github.com/VijayShankar22/CVE-2017-12542 | POC详情 |
暂无评论