CVE-2017-12542: HP Integrated Lights-Out 4 Firmware

Critical severity, CVSS 10.0. EPSS: 99.3% chance of exploitation in the next 30 days.

A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53 was found.

Affected products

  • HP Integrated Lights-Out 4 Firmware: before 2.53 (fixed in 2.53)

Published 2018-02-15. Last modified 2026-06-17.