HP iLO Web API Remote Code Execution

HPE has provided software updates to resolve the vulnerability in HPE Integrated Lights-out 4 (iLO 4). Upgrade to HPE Integrated Lights-out 4 (iLO 4) firmware version 2.53 or newer. The firmware is available to download here NOTE: The iLO for Moonshot 2.56 firmware is...

Insecure IPMI Implementation

Table of Contents Option 1: Disable the IPMI Service Option 2: Implement a Strong Password Option 3: Implement a Strong Password Policy Option 4: Implement a Configuration Management Policy This weakness is the result of a flaw in the protocol design. As a result,...

Weak or Default Credentials – SSH

Table of Contents Option 1: Implement a Strong Password Policy Option 2: Implement a Configuration Management Policy Option 1: Implement a Strong Password Policy Change the credential’s password and ensure a strong password policy is in place and users are properly...

Weak or Default Credentials – Cracked Credentials

Table of Contents Option 1: Implement a Strong Password Policy Option 2: Implement a Configuration Management Process Option 1: Implement a Strong Password Policy Change the credential’s password and ensure a strong password policy is in place and users are properly...

Weak NFS Export Permissions

Table of Contents Option 1: Disable the NFS Service Option 2: Restrict Access to the NFS Service Option 1: Disable the NFS Service Debian/Ubuntu From within a terminal: sudo service nfs-kernel-server stop sudo apt-get --purge remove nfs-kernel-server nfs-common...

Weak or Default Credentials – SNMP

Table of Contents Option 1: Disable the SNMP Service Option 2: Update the Community String to a Strong Password Option 1: Disable the SNMP Service If the service is not in use, the best mitigation is to disable it. With a wide variety of devices possible running the...

Guest Account Enabled

Table of Contents Option 1: Disable the Guest Account Option 2: Restrict the Guest Account Access Option 1: Disable the Guest Account If the Guest account is not in use, completely disable it by opening a Administrative command prompt on the host and issuing the...

Cisco Smart Install

Table of Contents Option 1: Upgrade IOS to a Secure Version Option 2: Disable the Smart Install Service Option 3: Apply Firewall Whitelist Rules Option 1: Upgrade IOS to a Secure Version If the hardware and licensing supports upgrading to a newer IOS version, follow...

How can NodeZero help you?

Let our experts walk you through a demonstration of NodeZero, so you can see how to put it to work for your company.