Known vulnerabilities in HPE Integrated Lights-Out 4 (iLO 4)

Vendor: HPE
Software CPE: cpe:2.3:h:hpe:hpe_integrated_lights-out_4_ilo_4:*:*:*:*:*:*:*:*
Total vulnerabilities: 7
Public exploits: 4
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting HPE Integrated Lights-Out 4 (iLO 4) HPE Integrated Lights-Out 4 (iLO 4) is affected by 7 known vulnerabilities: 1 high, 4 medium, 2 low Critical High Medium Low

Vulnerabilities (7)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU113675 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2022-23701
CWE-74 Medium
No
No
2.60 06.08.2025 SB2022021666
#VU61391 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2022-0778
CWE-835 Medium
Available
No
2.81 15.03.2022 SB2022031520
SB2022031522
SB2022031611
and 238 more
#VU12870 - Improper Resource Shutdown or Release
CVE-2015-5435
CWE-404 Low
No
No
2.22 21.05.2018 SB2015092301
SB2023041122
#VU10846 - Improper Authentication
CVE-2017-12543
CWE-287 Low
No
No
- 06.03.2018 SB2017082409
#VU8006 - Authentication Bypass Issues
CVE-2017-12542
CWE-592 High
Available
No
2.53 24.08.2017 SB2017082403
SB2023032422
#VU5214 - Use of a Broken or Risky Cryptographic Algorithm
CVE-2014-3566
CWE-327 Medium
Available
No
2.03 20.01.2017 SB2014101601
SB2014102102
SB2016022401
and 78 more
#VU86 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2015-4000
CWE-300 Medium
Available
No
2.30 04.07.2016 SB2015071003
SB2015070202
SB2015072201
and 36 more