7.2
CVSSv3

CVE-2018-7078

Published: 06/08/2018 Updated: 05/10/2018
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

A remote code execution was identified in HPE Integrated Lights-Out 4 (iLO 4) earlier than version v2.60 and HPE Integrated Lights-Out 5 (iLO 5) earlier than version v1.30.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

hp integrated_lights-out_5_firmware

hp integrated_lights-out_4_firmware

Github Repositories

Subverting your server through its BMC: the HPE iLO4 case Introduction iLO is the server management solution embedded in almost every HPE servers for more than 10 years It provides every feature required by a system administrator to remotely manage a server without having to reach it physically Such features include power management, remote system console, remote CD/DVD imag