CVE-2013-2338: HP Integrated Lights-Out 3 Firmware
High severity, CVSS 10.0. EPSS: 10.4% chance of exploitation in the next 30 days.
Unspecified vulnerability on HP Integrated Lights-Out 3 (aka iLO3) cards with firmware before 1.57 and 4 (aka iLO4) cards with firmware before 1.22, when Single-Sign-On (SSO) is used, allows remote attackers to execute arbitrary code via unknown vectors.
Affected products
- HP Integrated Lights-Out 3 Firmware: up to and including 1.55; version 1.00 only; version 1.05 only; version 1.20 only; version 1.26 only; version 1.28 only; …
- HP Integrated Lights-Out 4 Firmware: up to and including 1.20; version 1.11 only; version 1.13 only
Published 2013-06-14. Last modified 2026-06-16.