CVE-2018-7078
HIGHHPE Integrated Lights-Out 4 < 2.60 and iLO 5 < 1.30 - Remote Code Execution
Title source: llmDescription
A remote code execution was identified in HPE Integrated Lights-Out 4 (iLO 4) earlier than version v2.60 and HPE Integrated Lights-Out 5 (iLO 5) earlier than version v1.30.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03844en_us
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1041188
Scores
CVSS v3
7.2
EPSS
0.0326
EPSS Percentile
87.3%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Details
Status
published
Products (2)
hp/integrated_lights-out_4_firmware
< 2.60
hp/integrated_lights-out_5_firmware
< 1.30
Published
Aug 06, 2018
Tracked Since
Feb 18, 2026