HIGH · 8.6

CVE-2018-7093

A security vulnerability in HPE Integrated Lights-Out 3 prior to v1.90, iLO 4 prior to v2.60, iLO 5 prior to v1.30, Moonshot Chassis Manager firmware prior to v1.58, and Moonshot Component Pack prior ...

Vulnerability Description

A security vulnerability in HPE Integrated Lights-Out 3 prior to v1.90, iLO 4 prior to v2.60, iLO 5 prior to v1.30, Moonshot Chassis Manager firmware prior to v1.58, and Moonshot Component Pack prior to v2.55 could be remotely exploited to create a denial of service.

CVSS Score

8.6

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
HpIntegrated Lights-Out 3 Firmware< 1.90
HpIntegrated Lights-Out 4 Firmware< 2.60
HpIntegrated Lights-Out 5 Firmware< 1.30
HpMoonshot Chassis Manager Firmware< 1.58
HpIntegrated Lights-Out-
HpMoonshot Component Pack Firmware< 2.55
HpMoonshot Component Pack-

References

FAQ

What is CVE-2018-7093?

CVE-2018-7093 is a vulnerability with a CVSS score of 8.6 (HIGH). A security vulnerability in HPE Integrated Lights-Out 3 prior to v1.90, iLO 4 prior to v2.60, iLO 5 prior to v1.30, Moonshot Chassis Manager firmware prior to v1.58, and Moonshot Component Pack prior ...

How severe is CVE-2018-7093?

CVE-2018-7093 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-7093?

Check the references section above for vendor advisories and patch information. Affected products include: Hp Integrated Lights-Out 3 Firmware, Hp Integrated Lights-Out 4 Firmware, Hp Integrated Lights-Out 5 Firmware, Hp Moonshot Chassis Manager Firmware, Hp Integrated Lights-Out.