GPU VulnDB

Database/Firmware, BMC & network fabric

HPE iLO 7: remote user validation failure allows unauthenticated compromise of the management controller

CVSS 9.0CVE-2026-79820Firmware, BMC & network fabriccurated

Impact

A validation failure in iLO 7 lets a remote actor bypass user validation on the out-of-band management controller, with HPE scoring full confidentiality, integrity and availability loss and a scope change beyond the iLO itself. On a GPU host the BMC is the console, the virtual media path, the power control and the firmware update channel, so control of it means control of the node below the operating system - including re-imaging it or mounting virtual media regardless of what the tenant OS enforces. Because iLO sits on the management VLAN that typically spans the whole fleet, one reachable controller is a foothold against every node on that network. HPE's advisory text in this record is a single sentence; the precise flaw and the exact affected firmware versions are only in the HPE bulletin.

Who can reach it

Network-reachable iLO 7 management interface, no authentication required (AV:N/PR:N), though HPE rates attack complexity high. In practice this means anyone who can reach the management VLAN, including a tenant or workload that has been given a route to it.

What to do

Apply the iLO 7 firmware update named in HPE bulletin hpesbhf05163en_us. The record does not state the fixed firmware version, so take it from the bulletin. iLO firmware updates can usually be staged with the host running and activate on an iLO reset, but plan for a management-plane outage per node and verify the running version afterwards. Until then, confirm iLO interfaces are on an isolated management network with no tenant or internet reachability.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.