HPE has provided software updates to resolve the vulnerability in HPE Integrated Lights-out 4 (iLO 4). Upgrade to HPE Integrated Lights-out 4 (iLO 4) firmware version 2.53 or newer. The firmware is available to download here NOTE: The iLO for Moonshot 2.56 firmware is...
VMware vCenter vSAN Health Check Plugin Remote Code Execution Vulnerability
Table of Contents Option 1: For vCenter Server Appliances Option 2: For Windows-based vCenter Servers Option 1: For vCenter Server Appliances Connect to the vCSA using an SSH session and root credentials. Backup...
Insecure IPMI Implementation
Table of Contents Option 1: Disable the IPMI Service Option 2: Implement a Strong Password Option 3: Implement a Strong Password Policy Option 4: Implement a Configuration Management Policy This weakness is the result of a flaw in the protocol design. As a result,...
Group Policy Preference Password Elevation of Privilege Vulnerability
Table of Contents: Option 1: Patch the Host Option 2: Remove Old or Unused Policies Option 1: Patch the Host Microsoft released a patch, KB2928120, addressing this vulnerability. To install it, download the patch from the MS14-025 Security Bulletin for the...
Weak or Default Credentials – SSH
Table of Contents Option 1: Implement a Strong Password Policy Option 2: Implement a Configuration Management Policy Option 1: Implement a Strong Password Policy Change the credential’s password and ensure a strong password policy is in place and users are properly...
Weak or Default Credentials – Cracked Credentials
Table of Contents Option 1: Implement a Strong Password Policy Option 2: Implement a Configuration Management Process Option 1: Implement a Strong Password Policy Change the credential’s password and ensure a strong password policy is in place and users are properly...
Weak NFS Export Permissions
Table of Contents Option 1: Disable the NFS Service Option 2: Restrict Access to the NFS Service Option 1: Disable the NFS Service Debian/Ubuntu From within a terminal: sudo service nfs-kernel-server stop sudo apt-get --purge remove nfs-kernel-server nfs-common...
Weak or Default Credentials – SNMP
Table of Contents Option 1: Disable the SNMP Service Option 2: Update the Community String to a Strong Password Option 1: Disable the SNMP Service If the service is not in use, the best mitigation is to disable it. With a wide variety of devices possible running the...
Guest Account Enabled
Table of Contents Option 1: Disable the Guest Account Option 2: Restrict the Guest Account Access Option 1: Disable the Guest Account If the Guest account is not in use, completely disable it by opening a Administrative command prompt on the host and issuing the...
Cisco Smart Install
Table of Contents Option 1: Upgrade IOS to a Secure Version Option 2: Disable the Smart Install Service Option 3: Apply Firewall Whitelist Rules Option 1: Upgrade IOS to a Secure Version If the hardware and licensing supports upgrading to a newer IOS version, follow...
How can NodeZero help you?
Let our experts walk you through a demonstration of NodeZero, so you can see how to put it to work for your company.