CVE-2023-50272: HPE Integrated Lights-Out 5 Firmware

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

A potential security vulnerability has been identified in HPE Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 6 (iLO 6). The vulnerability could be remotely exploited to allow authentication bypass.

Affected products

  • HPE Integrated Lights-Out 5 Firmware: from 2.63, up to and including 3.00
  • HPE Integrated Lights-Out 6 Firmware: from 1.05, up to and including 1.55

Published 2023-12-19. Last modified 2026-06-17.