Vulnerabilities > HP > Integrated Lights OUT 4 Firmware
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-06-05 | CVE-2019-11983 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in HP products A remote buffer overflow vulnerability was identified in HPE Integrated Lights-Out 4 (iLO 4) earlier than v2.61b for Gen9 servers and Integrated Lights-Out 5 (iLO 5) for Gen10 Servers earlier than version v1.39. | 7.0 |
2019-06-05 | CVE-2019-11982 | Cross-site Scripting vulnerability in HP products A remote cross site scripting vulnerability was identified in HPE Integrated Lights-Out 4 (iLO 4) earlier than v2.61b for Gen9 servers and Integrated Lights-Out 5 (iLO 5) for Gen10 Servers earlier than version v1.39. | 8.3 |
2018-12-03 | CVE-2018-7112 | Unspecified vulnerability in HP products The HPE-provided Windows firmware installer for certain Gen9, Gen8, G7,and G6 HPE servers allows local disclosure of privileged information. | 5.5 |
2018-09-27 | CVE-2018-7105 | Unspecified vulnerability in HP products A security vulnerability in HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers prior to v1.35, HPE Integrated Lights-Out 4 (iLO 4) prior to v2.61, HPE Integrated Lights-Out 3 (iLO 3) prior to v1.90 could be remotely exploited to execute arbitrary code leading to disclosure of information. | 7.2 |
2018-09-27 | CVE-2018-7101 | Unspecified vulnerability in HP products A potential remote denial of service security vulnerability has been identified in HPE Integrated Lights Out 4 prior to v2.60 and iLO 5 for Gen 10 servers prior to v1.30. | 7.5 |
2018-08-14 | CVE-2018-7093 | Unspecified vulnerability in HP products A security vulnerability in HPE Integrated Lights-Out 3 prior to v1.90, iLO 4 prior to v2.60, iLO 5 prior to v1.30, Moonshot Chassis Manager firmware prior to v1.58, and Moonshot Component Pack prior to v2.55 could be remotely exploited to create a denial of service. | 8.6 |
2018-08-06 | CVE-2018-7078 | Unspecified vulnerability in HP products A remote code execution was identified in HPE Integrated Lights-Out 4 (iLO 4) earlier than version v2.60 and HPE Integrated Lights-Out 5 (iLO 5) earlier than version v1.30. | 7.2 |
2018-08-06 | CVE-2016-4406 | Cross-site Scripting vulnerability in HP products A remote cross site scripting vulnerability was identified in HPE iLO 3 all version prior to v1.88 and HPE iLO 4 all versions prior to v2.44. | 6.1 |
2018-02-15 | CVE-2017-12543 | Information Exposure vulnerability in HP products A remote disclosure of information vulnerability in Moonshot Remote Console Administrator Prior to 2.50, iLO4 prior to v2.53, iLO3 prior to v1.89 and iLO2 prior to v2.30 was found. | 6.5 |
2018-02-15 | CVE-2017-12542 | Unspecified vulnerability in HP Integrated Lights-Out 4 Firmware A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53 was found. | 10.0 |