CVE-2023-28083: HP Integrated Lights-Out 4

Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.

A remote Cross-site Scripting vulnerability was discovered in HPE Integrated Lights-Out 6 (iLO 6), Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 4 (iLO 4). HPE has provided software updates to resolve this vulnerability in HPE Integrated Lights-Out.

Affected products

  • HP Integrated Lights-Out 4: before 2.82 (fixed in 2.82)
  • HP Integrated Lights-Out 5: before 2.78 (fixed in 2.78)
  • HP Integrated Lights-Out 6: before 1.20 (fixed in 1.20)

Published 2023-03-22. Last modified 2026-06-17.