Description
A remote cross site scripting vulnerability was identified in HPE Integrated Lights-Out 4 (iLO 4) earlier than v2.61b for Gen9 servers and Integrated Lights-Out 5 (iLO 5) for Gen10 Servers earlier than version v1.39.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_confirm
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03917en_us
Scores
CVSS v3
8.3
EPSS
0.0060
EPSS Percentile
69.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Details
CWE
CWE-79
Status
published
Products (2)
hp/integrated_lights-out_4_firmware
< 2.61b
hp/integrated_lights-out_5_firmware
< 1.39
Published
Jun 05, 2019
Tracked Since
Feb 18, 2026