Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-7117


A remote Cross-Site Scripting in HPE iLO 5 Web User Interface vulnerability was identified in HPE Integrated Lights-Out 5 (iLO 5) for Gen10 ProLiant Servers earlier than version v1.40.


Published

2019-04-09T19:29:01.633

Last Modified

2024-11-21T04:11:40.383

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 6.1 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System hp integrated_lights-out_5_firmware < 1.40 Yes
Hardware hp proliant_bl460c_gen10 - No
Hardware hp proliant_dl120_gen10 - No
Hardware hp proliant_dl160_gen10 - No
Hardware hp proliant_dl180_gen10 - No
Hardware hp proliant_dl20_gen10 - No
Hardware hp proliant_dl325_gen10 - No
Hardware hp proliant_dl360_gen10 - No
Hardware hp proliant_dl380_gen10 - No
Hardware hp proliant_dl385_gen10 - No
Hardware hp proliant_dl560_gen10 - No
Hardware hp proliant_dl580_gen10 - No
Hardware hp proliant_microserver_gen10 - No
Hardware hp proliant_ml110_gen10 - No
Hardware hp proliant_ml30_gen10 - No
Hardware hp proliant_ml350_gen10 - No
Hardware hp proliant_xl170r_gen10 - No
Hardware hp proliant_xl190r_gen10 - No
Hardware hp proliant_xl230k_gen10 - No
Hardware hp proliant_xl450_gen10 - No

References