HPE / Aruba Integrated Lights-Out (iLO)

Our sources currently list 9 known vulnerabilities affecting HPE / Aruba Integrated Lights-Out (iLO).

Last updated: 22 July 2026, 20:35 AEST

No current ASD advisory names this product.That describes the Australian Signals Directorate’s publication record — it is not a statement that this product is free of vulnerabilities. See the list below.

Known vulnerabilities in HPE / Aruba Integrated Lights-Out (iLO), highest risk first.
CVESeverityExploitationPublishedSummary
CVE-2018-7101High (7.5)No exploitation reportedA potential remote denial of service security vulnerability has been identified in HPE Integrated Lights Out 4 prior to v2.60 and iLO 5 for Gen 10 servers prior to v1.30.
CVE-2018-7078High (7.2)No exploitation reportedA remote code execution was identified in HPE Integrated Lights-Out 4 (iLO 4) earlier than version v2.60 and HPE Integrated Lights-Out 5 (iLO 5) earlier than version v1.30.
CVE-2018-7105High (7.2)No exploitation reportedA security vulnerability in HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers prior to v1.35, HPE Integrated Lights-Out 4 (iLO 4) prior to v2.61, HPE Integrated Lights-Out …
CVE-2018-7093High (8.6)No exploitation reportedA security vulnerability in HPE Integrated Lights-Out 3 prior to v1.90, iLO 4 prior to v2.60, iLO 5 prior to v1.30, Moonshot Chassis Manager firmware prior to v1.58, and Moonshot C…
CVE-2019-11982High (8.3)No exploitation reportedA remote cross site scripting vulnerability was identified in HPE Integrated Lights-Out 4 (iLO 4) earlier than v2.61b for Gen9 servers and Integrated Lights-Out 5 (iLO 5) for Gen10…
CVE-2018-7117Medium (6.1)No exploitation reportedA remote Cross-Site Scripting in HPE iLO 5 Web User Interface vulnerability was identified in HPE Integrated Lights-Out 5 (iLO 5) for Gen10 ProLiant Servers earlier than version v1…
CVE-2019-11983High (7.0)No exploitation reportedA remote buffer overflow vulnerability was identified in HPE Integrated Lights-Out 4 (iLO 4) earlier than v2.61b for Gen9 servers and Integrated Lights-Out 5 (iLO 5) for Gen10 Serv…
CVE-2018-7113Medium (6.6)No exploitation reportedA security vulnerability in HPE Integrated Lights-Out 5 (iLO 5) prior to v1.37 could be locally exploited to bypass the security restrictions for firmware updates.
CVE-2021-46846Medium (6.4)No exploitation reportedCross Site Scripting vulnerability in Hewlett Packard Enterprise Integrated Lights-Out 5.

Vulnerability data from the NVD andCISA KEV(US Government, public domain); Australian advisories fromASD’s ACSC (CC BY 4.0). Exploit-probability scores from FIRST EPSS.

Let's talk

Running HPE / Aruba Integrated Lights-Out (iLO)?

Our Newcastle team can audit your HPE / Aruba estate, tell you in plain English which of these actually affect you, and patch them — fixed quote, no obligation.