CVE-2016-4406: XSS
Published Aug 6, 2018
·Updated
A remote cross site scripting vulnerability was identified in HPE iLO 3 all version prior to v1.88 and HPE iLO 4 all versions prior to v2.44.
Affected Software
3 affected components
HP Integrated Lights-out 3 Firmware<1.88
HP Integrated Lights-out 4 Firmware<2.44
HP Integrated Lights-Out
Event History
Aug 6, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for the remote cross site scripting vulnerability in HPE iLO?
The vulnerability ID for the remote cross site scripting vulnerability in HPE iLO is CVE-2016-4406.
2
Which versions of HPE iLO are affected by the remote cross site scripting vulnerability?
The remote cross site scripting vulnerability affects HPE iLO 3 versions prior to v1.88 and HPE iLO 4 versions prior to v2.44.
3
What is the severity rating of CVE-2016-4406?
The severity rating of CVE-2016-4406 is medium with a CVSS score of 6.1.
4
What is the Common Weakness Enumeration (CWE) ID for the vulnerability?
The Common Weakness Enumeration (CWE) ID for the vulnerability is CWE-79.
5
How can I fix the remote cross site scripting vulnerability in HPE iLO?
To fix the remote cross site scripting vulnerability, update HPE iLO 3 to version v1.88 or later, and HPE iLO 4 to version v2.44 or later.