VYPR

Integrated Lights-Out 5

by Arubanetworks

CVEs (10)

  • CVE-2017-12542CriFeb 15, 2018
    risk 0.76cvss 10.0epss 0.98

    A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53 was found.

  • CVE-2017-8979CriFeb 15, 2018
    risk 0.64cvss 9.8epss 0.04

    Security vulnerabilities in the HPE Integrated Lights-Out 2 (iLO 2) firmware could be exploited remotely to allow authentication bypass, code execution, and denial of service.

  • CVE-2022-28640HigSep 20, 2022
    risk 0.57cvss 8.8epss 0.01

    A potential local adjacent arbitrary code execution vulnerability that could potentially lead to a loss of confidentiality, integrity, and availability was discovered in HPE Integrated Lights-Out 5 (iLO 5) in Version: 2.71. Hewlett Packard Enterprise has provided updated…

  • CVE-2017-8987HigAug 6, 2018
    risk 0.56cvss 8.6epss 0.04

    A Unauthenticated Remote Denial of Service vulnerability was identified in HPE Integrated Lights-Out 3 (iLO 3) version v1.88 only. The vulnerability is resolved in iLO3 v1.89 or subsequent versions.

  • CVE-2022-28638HigSep 20, 2022
    risk 0.51cvss 7.8epss 0.00

    An isolated local disclosure of information and potential isolated local arbitrary code execution vulnerability that could potentially lead to a loss of confidentiality, integrity, and availability were discovered in HPE Integrated Lights-Out 5 (iLO 5) in Version: 2.71. Hewlett…

  • CVE-2022-28637HigSep 20, 2022
    risk 0.51cvss 7.8epss 0.00

    A local Denial of Service (DoS) and local arbitrary code execution vulnerability that could potentially lead to a loss of confidentiality, integrity, and availability were discovered in HPE Integrated Lights-Out 5 (iLO 5) in Version: 2.71. Hewlett Packard Enterprise has provided…

  • CVE-2018-7078HigAug 6, 2018
    risk 0.47cvss 7.2epss 0.06

    A remote code execution was identified in HPE Integrated Lights-Out 4 (iLO 4) earlier than version v2.60 and HPE Integrated Lights-Out 5 (iLO 5) earlier than version v1.30.

  • CVE-2021-46846MedDec 12, 2022
    risk 0.42cvss 6.4epss 0.01

    Cross Site Scripting vulnerability in Hewlett Packard Enterprise Integrated Lights-Out 5.

  • CVE-2017-12543MedFeb 15, 2018
    risk 0.42cvss 6.5epss 0.01

    A remote disclosure of information vulnerability in Moonshot Remote Console Administrator Prior to 2.50, iLO4 prior to v2.53, iLO3 prior to v1.89 and iLO2 prior to v2.30 was found.

  • CVE-2016-4406MedAug 6, 2018
    risk 0.40cvss 6.1epss 0.03

    A remote cross site scripting vulnerability was identified in HPE iLO 3 all version prior to v1.88 and HPE iLO 4 all versions prior to v2.44.