CVE-2018-7113: HP Integrated Lights-Out 5 Firmware

Medium severity, CVSS 6.6. EPSS: 0.7% chance of exploitation in the next 30 days.

A security vulnerability in HPE Integrated Lights-Out 5 (iLO 5) prior to v1.37 could be locally exploited to bypass the security restrictions for firmware updates.

Affected products

  • HP Integrated Lights-Out 5 Firmware: before 1.37 (fixed in 1.37)

Published 2018-12-03. Last modified 2026-06-17.