CVE-2014-2601: HP Integrated Lights-Out 2 Firmware

High severity, CVSS 7.8. EPSS: 4% chance of exploitation in the next 30 days.

The server in HP Integrated Lights-Out 2 (aka iLO 2) 2.23 and earlier allows remote attackers to cause a denial of service via crafted HTTPS traffic, as demonstrated by traffic from a CVE-2014-0160 vulnerability-assessment tool.

Affected products

  • HP Integrated Lights-Out 2 Firmware: up to and including 2.23; version 1.00 only; version 1.10 only; version 1.20 only; version 1.30 only; version 1.70 only; …

Published 2014-04-24. Last modified 2026-06-17.