HPE OneView may allow clusterService Authentication Bypass resulting in denial of service.
HPE OneView puede permitir la omisión de autenticación del servicio de clúster, lo que resulta en una denegación de servicio.
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Hewlett Packard Enterprise OneView. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the clusterService. The issue results from the lack of proper validation of the attacker's IP address, which results in exposure of functionality that should be available only on the loopback interface. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.