Vulnerability record · CVE-2017-12542 · published 15 February 2018
CVE-2017-12542: HPE iLO 4 authentication bypass and remote code execution
Hp · Integrated Lights Out 4 Firmware
HPE Integrated Lights-Out 4 (iLO 4) firmware before version 2.53 contains an authentication bypass that also allows execution of code. Because iLO is the out-of-band management interface for servers, a bypass there gives an unauthenticated network attacker control over the managed host.
Description
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53 was found.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 10.0 with network-reachable, unauthenticated code execution on server management controllers and a public exploit makes this a top remediation priority.
What it is
HPE Integrated Lights-Out 4 (iLO 4) firmware before version 2.53 contains an authentication bypass that also allows execution of code. Because iLO is the out-of-band management interface for servers, a bypass there gives an unauthenticated network attacker control over the managed host.
Impact
An attacker gains unauthenticated access to the iLO management interface and can execute code on it, which typically means control of the managed server's power, virtual media and console.
Attack surface
Reachable over the network via the iLO management interface (CVSS vector AV:N/PR:N/UI:N), requiring no authentication and no user interaction. The description does not specify the exact endpoint or protocol used.
Exploitation
A public exploit exists (Exploit-DB 44005) and EPSS is very high at 0.99294 (99.9th percentile), though the CVE is not listed in CISA KEV. No ransomware group use is documented in the record.
What to do
- Upgrade iLO 4 firmware to version 2.53 or later per the HPE advisory.
- Isolate iLO management interfaces on a dedicated management VLAN with no internet exposure.
- Restrict access to iLO with firewall rules and allowlists limited to trusted admin hosts.
- Change default iLO credentials and disable unused management services.
- Monitor the HPE advisory and vendor channels for any follow-up fixes.
Detection
- Alert on unexpected or anomalous requests to iLO management endpoints from non-admin source addresses.
- Audit iLO logs for authentication bypass patterns, new admin accounts, or configuration changes.
- Monitor for iLO firmware version below 2.53 across the server fleet.
- Watch for outbound connections or new processes originating from iLO management addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/100467 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039222 | Third Party AdvisoryVDB Entry |
| https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03769en_us | Vendor Advisory |
| https://www.exploit-db.com/exploits/44005/ | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/100467 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039222 | Third Party AdvisoryVDB Entry |
| https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03769en_us | Vendor Advisory |
| https://www.exploit-db.com/exploits/44005/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2017-12542 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-12542), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.