CVE-2018-7105: HP Integrated Lights-Out 3 Firmware
High severity, CVSS 7.2. EPSS: 4.1% chance of exploitation in the next 30 days.
A security vulnerability in HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers prior to v1.35, HPE Integrated Lights-Out 4 (iLO 4) prior to v2.61, HPE Integrated Lights-Out 3 (iLO 3) prior to v1.90 could be remotely exploited to execute arbitrary code leading to disclosure of information.
Affected products
- HP Integrated Lights-Out 3 Firmware: before 1.90 (fixed in 1.90)
- HP Integrated Lights-Out 4 Firmware: before 2.61 (fixed in 2.61)
- HP Integrated Lights-Out 5 Firmware: before 1.35 (fixed in 1.35)
Published 2018-09-27. Last modified 2026-06-17.