HPE / Aruba Integrated Lights-Out (iLO)
Our sources currently list 9 known vulnerabilities affecting HPE / Aruba Integrated Lights-Out (iLO).
Last updated: 22 July 2026, 20:35 AEST
No current ASD advisory names this product.That describes the Australian Signals Directorate’s publication record — it is not a statement that this product is free of vulnerabilities. See the list below.
| CVE | Severity | Exploitation | Published | Summary |
|---|---|---|---|---|
| CVE-2018-7101 | High (7.5) | No exploitation reported | A potential remote denial of service security vulnerability has been identified in HPE Integrated Lights Out 4 prior to v2.60 and iLO 5 for Gen 10 servers prior to v1.30. | |
| CVE-2018-7078 | High (7.2) | No exploitation reported | A remote code execution was identified in HPE Integrated Lights-Out 4 (iLO 4) earlier than version v2.60 and HPE Integrated Lights-Out 5 (iLO 5) earlier than version v1.30. | |
| CVE-2018-7105 | High (7.2) | No exploitation reported | A security vulnerability in HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers prior to v1.35, HPE Integrated Lights-Out 4 (iLO 4) prior to v2.61, HPE Integrated Lights-Out … | |
| CVE-2018-7093 | High (8.6) | No exploitation reported | A security vulnerability in HPE Integrated Lights-Out 3 prior to v1.90, iLO 4 prior to v2.60, iLO 5 prior to v1.30, Moonshot Chassis Manager firmware prior to v1.58, and Moonshot C… | |
| CVE-2019-11982 | High (8.3) | No exploitation reported | A remote cross site scripting vulnerability was identified in HPE Integrated Lights-Out 4 (iLO 4) earlier than v2.61b for Gen9 servers and Integrated Lights-Out 5 (iLO 5) for Gen10… | |
| CVE-2018-7117 | Medium (6.1) | No exploitation reported | A remote Cross-Site Scripting in HPE iLO 5 Web User Interface vulnerability was identified in HPE Integrated Lights-Out 5 (iLO 5) for Gen10 ProLiant Servers earlier than version v1… | |
| CVE-2019-11983 | High (7.0) | No exploitation reported | A remote buffer overflow vulnerability was identified in HPE Integrated Lights-Out 4 (iLO 4) earlier than v2.61b for Gen9 servers and Integrated Lights-Out 5 (iLO 5) for Gen10 Serv… | |
| CVE-2018-7113 | Medium (6.6) | No exploitation reported | A security vulnerability in HPE Integrated Lights-Out 5 (iLO 5) prior to v1.37 could be locally exploited to bypass the security restrictions for firmware updates. | |
| CVE-2021-46846 | Medium (6.4) | No exploitation reported | Cross Site Scripting vulnerability in Hewlett Packard Enterprise Integrated Lights-Out 5. |
Vulnerability data from the NVD andCISA KEV(US Government, public domain); Australian advisories fromASD’s ACSC (CC BY 4.0). Exploit-probability scores from FIRST EPSS.
Let's talk
Running HPE / Aruba Integrated Lights-Out (iLO)?
Our Newcastle team can audit your HPE / Aruba estate, tell you in plain English which of these actually affect you, and patch them — fixed quote, no obligation.
