Database/Control plane, storage & DevOps

HPE iLO4 / iLO5: Remote code execution on the management controller
CVSS 7.2CVE-2018-7078Control plane, storage & DevOpscurated
Impact
Remote code execution on the management controller
Who can reach it
Network, authenticated
What to do
iLO firmware update (iLO4 <2.60, iLO5 <1.30)
References
Related entries
- HPE iLO3/4/5: Arbitrary code execution on the iLOCVE-2018-7105 · HPE iLO3/4/5High
- NetApp ONTAP Select Deploy administration utility (privilege escalation): An administrative user of the Deploy utilityCVE-2019-17272 · NetApp ONTAP Select Deploy administration utility (privilege escalation)High
- Ceph MON (CephX authentication): The monitor does not sanitize other_keys when handling CEPHX_GET_AUTH_SESSION_KEY, soCVE-2021-20288 · Ceph MON (CephX authentication)High
- AMD PSP1 Configuration Block (APCB) parsing: An out-of-bounds memory write while the platform processes the AMD PSP1CVE-2021-26344 · AMD PSP1 Configuration Block (APCB) parsingHigh
- Schneider Electric StruxureWare Data Center Expert (V7.9.2 and prior) - network settings endpoint: Code injectionCVE-2023-25549 · Schneider Electric StruxureWare Data Center Expert (V7.9.2 and prior) - network settings endpointHigh
- Lenovo ThinkSystem SMM / SMM2 and FPC (command injection): An authenticated user with elevated privileges executesCVE-2024-2659 · Lenovo ThinkSystem SMM / SMM2 and FPC (command injection)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.