Database/Control plane, storage & DevOps

HPE iLO3/4/5: Remote unauthenticated denial of service against the management controller
CVSS 8.6CVE-2018-7093Control plane, storage & DevOpscurated
Impact
Remote unauthenticated denial of service against the management controller — loses out-of-band access to the node during an incident
Who can reach it
Network, unauthenticated
What to do
iLO firmware update; DoS on the BMC is an availability problem specifically because it removes the recovery path
References
Related entries
- HPE iLO3/4/5: Arbitrary code execution on the iLOCVE-2018-7105 · HPE iLO3/4/5High
- NAKIVO Backup & Replication: Unauthenticated absolute path traversal via getImageByPathCVE-2024-48248 · NAKIVO Backup & ReplicationHigh
- Socomec DIRIS Digiware M-70 1.6.9 (Modbus TCP and Modbus RTU-over-TCP): A large cluster of unauthenticated ModbusCVE-2024-48882 · Socomec DIRIS Digiware M-70 1.6.9 (Modbus TCP and Modbus RTU-over-TCP)High
- Ivanti Endpoint Manager (EPM): Auth bypass via alternate pathCVE-2026-1603 · Ivanti Endpoint Manager (EPM)High
- Pure Storage FlashArray Purity (management interface privilege bypass): An authenticated low-privileged user reachesCVE-2026-6444 · Pure Storage FlashArray Purity (management interface privilege bypass)High
- rclone (serve restic): Path validation in serve restic is incomplete, so an authenticated caller escapes the configuredCVE-2026-71309 · rclone (serve restic)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.