CVE-2024-20906Corporation SSM Ilom Integrated Lights OUT Manager vulnerability

4 documents4 sources
Severity
4.8MEDIUMNVD
EPSS
0.2%
top 58.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 16
Latest updateJan 17

Description

Vulnerability in the Integrated Lights Out Manager (ILOM) product of Oracle Systems (component: System Management). Supported versions that are affected are 3, 4 and 5. Easily exploitable vulnerability allows high privileged attacker with network access via ICMP to compromise Integrated Lights Out Manager (ILOM). Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Integrated Lights Out Manager (ILOM), attacks may significantly impa

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:NExploitability: 1.7 | Impact: 2.7

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-jj54-m9rr-8gjf: Vulnerability in the Integrated Lights Out Manager (ILOM) product of Oracle Systems (component: System Management)2024-01-17
CVEList
CVE-2024-20906: Vulnerability in the Integrated Lights Out Manager (ILOM) product of Oracle Systems (component: System Management)2024-01-16

📋Vendor Advisories

1
Oracle
Oracle Oracle Systems Risk Matrix: System Management — CVE-2024-209062024-01-15
CVE-2024-20906 — MEDIUM severity | cvebase