Low severity3.7NVD Advisory· Published Sep 8, 2016· Updated Jun 17, 2026
CVE-2016-4379
CVE-2016-4379
Description
The TLS implementation in HPE Integrated Lights-Out 3 (aka iLO3) firmware before 1.88 does not properly use a MAC protection mechanism in conjunction with CBC padding, which allows remote attackers to obtain sensitive information via a padding-oracle attack, aka a Vaudenay attack.
Affected products
2- cpe:2.3:o:hp:integrated_lights-out_3_firmware:*:*:*:*:*:*:*:*Range: <=1.87
- Range: <1.88
Patches
Vulnerability mechanics
References
4- h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplaynvdVendor Advisory
- www.iacr.org/archive/eurocrypt2002/23320530/cbc02_e02d.pdfnvdTechnical Description
- www.securityfocus.com/bid/92696nvd
- www.securitytracker.com/id/1036707nvd
News mentions
0No linked articles in our index yet.