CVE-2016-4406: HP Integrated Lights-Out 3 Firmware

Medium severity, CVSS 6.1. EPSS: 2.6% chance of exploitation in the next 30 days.

A remote cross site scripting vulnerability was identified in HPE iLO 3 all version prior to v1.88 and HPE iLO 4 all versions prior to v2.44.

Affected products

  • HP Integrated Lights-Out 3 Firmware: before 1.88 (fixed in 1.88)
  • HP Integrated Lights-Out 4 Firmware: before 2.44 (fixed in 2.44)

Published 2018-08-06. Last modified 2026-06-17.