First published: Mon Aug 06 2018(Updated: )
A remote code execution was identified in HPE Integrated Lights-Out 4 (iLO 4) earlier than version v2.60 and HPE Integrated Lights-Out 5 (iLO 5) earlier than version v1.30.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hp Integrated Lights-out 4 Firmware | <2.60 | |
Hp Integrated Lights-out 5 Firmware | <1.30 | |
Hp Integrated Lights-out |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7078 is a vulnerability that allows remote code execution in HPE Integrated Lights-Out 4 (iLO 4) firmware versions earlier than v2.60 and HPE Integrated Lights-Out 5 (iLO 5) firmware versions earlier than v1.30.
CVE-2018-7078 has a severity rating of 7.2 out of 10, indicating a critical vulnerability.
CVE-2018-7078 affects HPE Integrated Lights-Out 4 (iLO 4) firmware versions earlier than v2.60 and HPE Integrated Lights-Out 5 (iLO 5) firmware versions earlier than v1.30.
To fix CVE-2018-7078, upgrade your HPE Integrated Lights-Out 4 (iLO 4) firmware to at least v2.60 and HPE Integrated Lights-Out 5 (iLO 5) firmware to at least v1.30.
You can find more information about CVE-2018-7078 on the SecurityTracker website (http://www.securitytracker.com/id/1041188) and the HPE support website (https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03844en_us).