CVE-2016-4379: HP Integrated Lights-Out 3 Firmware
Low severity, CVSS 3.7. EPSS: 1.6% chance of exploitation in the next 30 days.
The TLS implementation in HPE Integrated Lights-Out 3 (aka iLO3) firmware before 1.88 does not properly use a MAC protection mechanism in conjunction with CBC padding, which allows remote attackers to obtain sensitive information via a padding-oracle attack, aka a Vaudenay attack.
Affected products
- HP Integrated Lights-Out 3 Firmware: up to and including 1.87
Published 2016-09-08. Last modified 2026-06-17.