Vulnerabilities > HP > Integrated Lights OUT 3 Firmware > 1.28
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-12-03 | CVE-2018-7112 | Unspecified vulnerability in HP products The HPE-provided Windows firmware installer for certain Gen9, Gen8, G7,and G6 HPE servers allows local disclosure of privileged information. | 4.9 |
2018-09-27 | CVE-2018-7105 | Unspecified vulnerability in HP products A security vulnerability in HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers prior to v1.35, HPE Integrated Lights-Out 4 (iLO 4) prior to v2.61, HPE Integrated Lights-Out 3 (iLO 3) prior to v1.90 could be remotely exploited to execute arbitrary code leading to disclosure of information. | 9.0 |
2018-08-14 | CVE-2018-7093 | Unspecified vulnerability in HP products A security vulnerability in HPE Integrated Lights-Out 3 prior to v1.90, iLO 4 prior to v2.60, iLO 5 prior to v1.30, Moonshot Chassis Manager firmware prior to v1.58, and Moonshot Component Pack prior to v2.55 could be remotely exploited to create a denial of service. | 7.8 |
2018-08-06 | CVE-2016-4406 | Cross-site Scripting vulnerability in HP products A remote cross site scripting vulnerability was identified in HPE iLO 3 all version prior to v1.88 and HPE iLO 4 all versions prior to v2.44. | 4.3 |
2018-02-15 | CVE-2017-12543 | Information Exposure vulnerability in HP products A remote disclosure of information vulnerability in Moonshot Remote Console Administrator Prior to 2.50, iLO4 prior to v2.53, iLO3 prior to v1.89 and iLO2 prior to v2.30 was found. | 4.0 |
2016-09-08 | CVE-2016-4379 | Cryptographic Issues vulnerability in HP Integrated Lights-Out 3 Firmware The TLS implementation in HPE Integrated Lights-Out 3 (aka iLO3) firmware before 1.88 does not properly use a MAC protection mechanism in conjunction with CBC padding, which allows remote attackers to obtain sensitive information via a padding-oracle attack, aka a Vaudenay attack. | 4.3 |
2015-09-30 | CVE-2015-5435 | Remote Denial of Service vulnerability in HP products Unspecified vulnerability in HP Integrated Lights-Out (iLO) firmware 3 before 1.85 and 4 before 2.22 allows remote authenticated users to cause a denial of service via unknown vectors. | 4.0 |
2015-03-31 | CVE-2015-2106 | Security vulnerability in HP products Unspecified vulnerability in HP Integrated Lights-Out (iLO) firmware 2 before 2.27, 3 before 1.82, and 4 before 2.10 allows remote attackers to bypass intended access restrictions or cause a denial of service via unknown vectors. | 6.4 |
2013-06-14 | CVE-2013-2338 | Remote Unauthorized Access vulnerability in HP products Unspecified vulnerability on HP Integrated Lights-Out 3 (aka iLO3) cards with firmware before 1.57 and 4 (aka iLO4) cards with firmware before 1.22, when Single-Sign-On (SSO) is used, allows remote attackers to execute arbitrary code via unknown vectors. | 10.0 |
2012-11-29 | CVE-2012-3271 | Information Disclosure vulnerability in HP products Unspecified vulnerability on the HP Integrated Lights-Out 3 (aka iLO3) with firmware before 1.50 and Integrated Lights-Out 4 (aka iLO4) with firmware before 1.13 allows remote attackers to obtain sensitive information via unknown vectors. | 9.3 |