Impact
A potential denial of service vulnerability exists in HPE Integrated Lights‑Out 6 (iLO 6) firmware prior to version 1.78. The flaw can cause the iLO management console to become unresponsive, disrupting remote administration and impacting system availability. This weakness is a type of uncontrolled resource consumption (CWE‑400).
Affected Systems
All iLO 6 firmware releases earlier than v1.78 are affected; firmware v1.78 and newer are not impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. No EPSS score is published, so current exploitation likelihood cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploitation. As iLO is accessed over the network, the attack vector is inferred to be remote, likely through the management interface, with no additional prerequisites mentioned in the advisory.
OpenCVE Enrichment