CVE-2017-12542

CRITICAL EXPLOITED IN THE WILD RANSOMWARE NUCLEI

HP Integrated Lights-out 4 Firmware < 2.53 - Authentication Bypass

Title source: rule

Description

A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53 was found.

Exploits (6)

exploitdb WORKING POC
by skelsec · pythonremotemultiple
https://www.exploit-db.com/exploits/44005
nomisec WORKING POC 89 stars
by skelsec · remote
https://github.com/skelsec/CVE-2017-12542
nomisec SCANNER 5 stars
by sk1dish · remote
https://github.com/sk1dish/ilo4-rce-vuln-scanner
nomisec WORKING POC
by Gill-Singh-A · remote
https://github.com/Gill-Singh-A/CVE-2017-12542-Exploit
nomisec WORKING POC
by VijayShankar22 · remote
https://github.com/VijayShankar22/CVE-2017-12542
metasploit WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/hp/hp_ilo_create_admin_account.rb

Nuclei Templates (1)

HPE Integrated Lights-out 4 (ILO4) <2.53 - Authentication Bypass
CRITICALby pikpikcu

Scores

CVSS v3 10.0
EPSS 0.9425
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Details

VulnCheck KEV 2021-04-12
InTheWild.io 2022-05-25
Ransomware Use Confirmed
Status published
Products (1)
hp/integrated_lights-out_4_firmware < 2.53
Published Feb 15, 2018
Tracked Since Feb 18, 2026