CVE-2017-12543: HP Integrated Lights-Out 2 Firmware

Medium severity, CVSS 6.5. EPSS: 1.4% chance of exploitation in the next 30 days.

A remote disclosure of information vulnerability in Moonshot Remote Console Administrator Prior to 2.50, iLO4 prior to v2.53, iLO3 prior to v1.89 and iLO2 prior to v2.30 was found.

Affected products

  • HP Integrated Lights-Out 2 Firmware: before 2.30 (fixed in 2.30)
  • HP Integrated Lights-Out 3 Firmware: before 1.89 (fixed in 1.89)
  • HP Integrated Lights-Out 4 Firmware: before 2.53 (fixed in 2.53)
  • HP Moonshot Remote Console Administrator: before 2.50 (fixed in 2.50)

Published 2018-02-15. Last modified 2026-06-17.