CVE-2018-7093
A security vulnerability in HPE Integrated Lights-Out 3 prior to v1.90, iLO 4 prior to v2.60, iLO 5 prior to v1.30, Moonshot Chassis Manager firmware prior to v1.58, and Moonshot Component Pack prior to v2.55 could be remotely exploited to create a…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.45%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A security vulnerability in HPE Integrated Lights-Out 3 prior to v1.90, iLO 4 prior to v2.60, iLO 5 prior to v1.30, Moonshot Chassis Manager firmware prior to v1.58, and Moonshot Component Pack prior to v2.55 could be remotely exploited to create a denial of service.
- CVSS 3.0
- 8.6 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
- EPSS
- 3.45% probability · 88th percentile
- CISA KEV
- Not listed
- Affected
- hp/integrated lights-out 3 firmware · hp/integrated lights-out 4 firmware · hp/integrated lights-out 5 firmware · hp/moonshot chassis manager firmware · hp/moonshot component pack firmware
- Source
- security-alert@hpe.com
References
- http://www.securitytracker.com/id/1041435Third Party Advisory, VDB Entry
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03835en_usVendor Advisory
- http://www.securitytracker.com/id/1041435Third Party Advisory, VDB Entry
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03835en_usVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.