Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
64 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.7) | 1.6% | — | HP Integrated Lights-out 3 Firmware | 8/9/2016 | 17/6/2026 | The TLS implementation in HPE Integrated Lights-Out 3 (aka iLO3) firmware before 1.88 does not properly use a MAC protection mechanism in conjunction with CBC padding, which allows remote attackers to obtain sensitive information via a padding-oracle attack, aka a Vaudenay attack. | |
| Modificada | Crítica (9.8) | 3.0% | — | HP Integrated Lights-out 3 FirmwareHP Integrated Lights-out 4 FirmwareHP Integrated Lights-out 4 Mrca Firmware | 8/9/2016 | 17/6/2026 | Multiple unspecified vulnerabilities in HPE Integrated Lights-Out 3 (aka iLO 3) firmware before 1.88, Integrated Lights-Out 4 (aka iLO 4) firmware before 2.44, and Integrated Lights-Out 4 (aka iLO 4) mRCA firmware before 2.32 allow remote attackers to obtain sensitive information, modify data, or cause a denial of… | |
| Modificada | Media (4) | 2.4% | — | HP Integrated Lights-out 3 FirmwareHP Integrated Lights-out 4 Firmware | 30/9/2015 | 17/6/2026 | Unspecified vulnerability in HP Integrated Lights-Out (iLO) firmware 3 before 1.85 and 4 before 2.22 allows remote authenticated users to cause a denial of service via unknown vectors. | |
| Modificada | Media (6.4) | 3.5% | — | HP Integrated Lights-out 2 FirmwareHP Integrated Lights-out 3 FirmwareHP Integrated Lights-out 4 Firmware | 31/3/2015 | 17/6/2026 | Unspecified vulnerability in HP Integrated Lights-Out (iLO) firmware 2 before 2.27, 3 before 1.82, and 4 before 2.10 allows remote attackers to bypass intended access restrictions or cause a denial of service via unknown vectors. | |
| Modificada | Alta (10) | 13% | — | HP Integrated Lights-out 2 FirmwareHP Integrated Lights-out 4 FirmwareHP Integrated Lights-out Chassis Management Firmware | 31/3/2015 | 17/6/2026 | Unspecified vulnerability in HP Integrated Lights-Out (iLO) firmware 2 before 2.27 and 4 before 2.03 and iLO Chassis Management (CM) firmware before 1.30 allows remote attackers to gain privileges, execute arbitrary code, or cause a denial of service via unknown vectors. | |
| Modificada | Alta (7.8) | 4.0% | — | HP Integrated Lights-out 2 Firmware | 24/4/2014 | 17/6/2026 | The server in HP Integrated Lights-Out 2 (aka iLO 2) 2.23 and earlier allows remote attackers to cause a denial of service via crafted HTTPS traffic, as demonstrated by traffic from a CVE-2014-0160 vulnerability-assessment tool. | |
| Modificada | Media (6.8) | 1.8% | — | HP Integrated Lights-out FirmwareHP Integrated Lights-out 4 | 18/11/2013 | 16/6/2026 | Unspecified vulnerability in HP Integrated Lights-Out 4 (iLO4) with firmware before 1.32 allows remote authenticated users to obtain sensitive information via unknown vectors. | |
| Modificada | Media (4.3) | 2.3% | — | HP Integrated Lights-out FirmwareHP Integrated Lights-out 4 | 18/11/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in HP Integrated Lights-Out 4 (iLO4) with firmware before 1.32 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (9) | 3.0% | — | HP Integrated Lights-out Firmware | 5/8/2013 | 16/6/2026 | Unspecified vulnerability in HP Integrated Lights-Out 3 (aka iLO3) firmware before 1.60 and 4 (aka iLO4) firmware before 1.30 allows remote attackers to bypass authentication via unknown vectors. | |
| Modificada | Alta (10) | 50% | 💥 PoC | HP Integrated Lights-out BMC | 8/7/2013 | 16/6/2026 | The HP Integrated Lights-Out (iLO) BMC implementation allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher suite 0 (aka cipher zero) and an arbitrary password. | |
| Modificada | Alta (10) | 10% | — | HP Integrated Lights-out 3 FirmwareHP Integrated Lights-out 4 Firmware | 14/6/2013 | 16/6/2026 | Unspecified vulnerability on HP Integrated Lights-Out 3 (aka iLO3) cards with firmware before 1.57 and 4 (aka iLO4) cards with firmware before 1.22, when Single-Sign-On (SSO) is used, allows remote attackers to execute arbitrary code via unknown vectors. | |
| Modificada | Alta (9.3) | 5.1% | — | HP Integrated Lights-out 3 FirmwareHP Integrated Lights-out 4 Firmware | 29/11/2012 | 16/6/2026 | Unspecified vulnerability on the HP Integrated Lights-Out 3 (aka iLO3) with firmware before 1.50 and Integrated Lights-Out 4 (aka iLO4) with firmware before 1.13 allows remote attackers to obtain sensitive information via unknown vectors. | |
| Modificada | Alta (9) | 2.0% | — | SUN Integrated Lights-out ManagerSUN Blade 6000 Modular System With ChassisSUN Blade 6048 Modular System With ChassisSUN Blade 8000 Modular System+33 | 23/10/2008 | 16/6/2026 | Unspecified vulnerability in Sun Integrated Lights-Out Manager (ILOM) 2.0.1.5 through 2.0.4.26 allows remote authenticated users to (1) access the service processor (SP) and cause a denial of service (shutdown or reboot), or (2) access the host operating system and have an unspecified impact, via unknown vectors. | |
| Modificada | Media (5) | 2.7% | — | HP Integrated Lights-out Firmware | 6/8/2004 | 16/6/2026 | HP Integrated Lights-Out (iLO) 1.10 and other versions before 1.55 allows remote attackers to cause a denial of service (hang) by accessing iLO using the TCP/IP reserved port zero. |