A critical vulnerability, CVE-2024-540385, has been found in HPE Cray XD670 servers using the AMI BMC Redfish API, allowing remote authentication bypass. Administrators must act quickly to prevent the exploitation.
According to HPE’s security bulletin, “This vulnerability could be remotely exploited to allow authentication bypass.” An attacker could gain unauthorized access to the server’s baseboard management controller (BMC) without valid credentials. This is serious because the BMC allows for system management tasks like power control, remote console access, and hardware monitoring.
By infosecbulletin
/ Wednesday , June 18 2025
Russian cybersecurity experts discovered the first local data theft attacks using a modified version of legitimate near field communication (NFC)...
Read More
By infosecbulletin
/ Tuesday , June 17 2025
Cybersecurity researcher Jeremiah Fowler discovered an unsecured database with 170,360 records belonging to a real estate company. It contained personal...
Read More
By infosecbulletin
/ Tuesday , June 17 2025
GreyNoise found attempts to exploit CVE-2023-28771, a vulnerability in Zyxel's IKE affecting UDP port 500. The attack centers around CVE-2023-28771,...
Read More
By infosecbulletin
/ Tuesday , June 17 2025
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently included two high-risk vulnerabilities in its Known Exploited Vulnerabilities (KEV)...
Read More
By infosecbulletin
/ Monday , June 16 2025
SafetyDetectives’ Cybersecurity Team discovered a public post on a clear web forum in which a threat actor claimed to have...
Read More
By infosecbulletin
/ Sunday , June 15 2025
WestJet, Canada's second-largest airline, is looking into a cyberattack that has affected some internal systems during its response to the...
Read More
By infosecbulletin
/ Saturday , June 14 2025
Resecurity found 7.4 million records of Paraguayan citizens' personal information leaked on the dark web today. Last week, cybercriminals attempted...
Read More
By infosecbulletin
/ Friday , June 13 2025
HashiCorp has revealed a critical vulnerability in its Nomad tool that may let attackers gain higher privileges by misusing the...
Read More
By infosecbulletin
/ Friday , June 13 2025
SoftBank has disclosed that personal information of more than 137,000 mobile subscribers—covering names, addresses, and phone numbers—might have been leaked...
Read More
By infosecbulletin
/ Friday , June 13 2025
Serious security vulnerabilities in Trend Micro Apex One could allow attackers to inject malicious code and elevate their privileges within...
Read More
This vulnerability poses a significant risk, particularly in high-performance computing environments using HPE Cray XD670 servers. If exploited, attackers could gain full control of these servers, resulting in data breaches and system disruptions.
The vulnerability impacts HPE Cray XD670 systems prior to BMC version 1.19. HPE has quickly released an updated BMC firmware, version 1.19, on January 29, 2025, to fix the issue.
HPE urges administrators to promptly update their BMC firmware to the patched version. The bulletin provides a clear procedure for obtaining the required firmware.
Click the following link: Hewlett Packard Enterprise Support Center
Enter a product name from the list of impacted products above in the text search field and wait for a list of Suggested Products to display
The page should refresh to include a selection for the “DRIVERS AND SOFTWARE” tab
Select the “DRIVERS AND SOFTWARE tab to find the components that you need and download them.
This process helps administrators quickly find and download the right firmware for their HPE Cray XD670 servers.