CVE-2017-12542 is a critical authentication bypass and remote code execution vulnerability in HPE Integrated Lights-Out 4 (iLO 4) versions up to and including 2.52. The flaw allows remote, unauthenticated attackers to bypass authentication mechanisms and execute arbitrary code on the iLO management controller. Exploitation can lead to full compromise of the iLO system, and, via DMA, compromise of the host operating system. The vulnerability is classified as CWE-269 (Improper Privilege Management) and is trivially exploitable over the network. Public exploits and analysis tools are available.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a small standalone Python proof-of-concept exploit for HP iLO authentication bypass CVE-2017-12542. The repository contains three files: a README with vulnerability and usage notes, a requirements file listing requests and colorama, and a single executable script, main.py, which implements all exploit logic. The script accepts a target server URL, supports a check mode, and optionally performs exploitation by creating a new user. It normalizes the supplied target using urlparse and then interacts directly with the HP iLO REST API. In check mode, it sends an unauthenticated GET request to /rest/v1/AccountService/Accounts with a randomized Connection header value. If the target returns HTTP 200, the script treats the host as vulnerable and parses the JSON response to enumerate existing usernames from the Items array. In exploitation mode, the script sends an unauthenticated POST request to the same endpoint with a JSON payload defining a new account. The payload grants extensive privileges including login, remote console, user configuration, virtual media, virtual power/reset, and iLO configuration rights. If no password is supplied, the script generates a random 20-character alphanumeric password. A successful exploit is identified by HTTP 201. There is no shellcode, command execution, persistence, or post-exploitation framework integration. The exploit is focused entirely on abusing the iLO REST API to bypass authentication, enumerate accounts, and create a privileged management user. Because it includes a working exploitation path with a hardcoded privilege structure but no flexible payload framework, the maturity is best classified as OPERATIONAL.
This repository contains a Python exploit script (exploit.py) and a brief README.md. The script targets HP iLO servers vulnerable to CVE-2017-12542, an authentication bypass vulnerability. The exploit works in two stages: first, it checks if the target iLO server is vulnerable by sending a specially crafted GET request to the /rest/v1/AccountService/Accounts endpoint with a manipulated 'Connection' header. If the server is vulnerable, the script can then send a POST request to the same endpoint to create a new admin user with full privileges, using user-supplied credentials. The script is interactive, prompting the user for the target IP, and, if desired, the new admin username and password. The only fingerprintable endpoint is the iLO REST API path used for both detection and exploitation. The repository is straightforward, with the main exploit logic contained in exploit.py, and is operational as it provides a working payload to gain admin access on vulnerable HP iLO servers.
This repository contains a single Metasploit auxiliary module targeting HP iLO 4 devices (firmware versions 1.00 to 2.50) vulnerable to CVE-2017-12542. The exploit leverages an authentication bypass via a buffer overflow in the Connection HTTP header, allowing unauthenticated access to the REST API. The module then creates a new administrator account with full privileges by sending a crafted POST request to the /rest/v1/AccountService/Accounts endpoint. The code is written in Ruby and is structured as a standard Metasploit module, with options for specifying the username and password for the new account. The exploit is operational and provides attackers with full administrative access to affected HP iLO 4 devices.
This repository contains a Python exploit script (exploit_1.py) targeting CVE-2017-12542, a remote code execution and privilege escalation vulnerability in HP Integrated Lights-Out 4 (iLO4) management interfaces. The exploit abuses improper authentication handling in the iLO4 REST API, specifically the /rest/v1/AccountService/Accounts endpoint, by sending a malformed 'Connection' header to bypass authentication. The script provides two main functionalities: (1) testing if a target is vulnerable by listing user accounts, and (2) exploiting the vulnerability to create a new administrator user with attacker-supplied credentials. The exploit operates over HTTPS and disables SSL verification to accommodate self-signed certificates commonly used by iLO interfaces. The repository is structured simply, with a single code file, a README describing the CVE, and standard license and gitignore files. The exploit is operational and can be used to gain full administrative access to vulnerable HP iLO4 devices.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.