Description
A potential denial of service vulnerability exists in HPE Integrated Lights-Out 6 (iLO 6) prior to v1.78.
Published: 2026-08-05
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A potential denial of service vulnerability exists in HPE Integrated Lights‑Out 6 (iLO 6) firmware prior to version 1.78. The flaw can cause the iLO management console to become unresponsive, disrupting remote administration and impacting system availability. This weakness is a type of uncontrolled resource consumption (CWE‑400).

Affected Systems

All iLO 6 firmware releases earlier than v1.78 are affected; firmware v1.78 and newer are not impacted.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. No EPSS score is published, so current exploitation likelihood cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploitation. As iLO is accessed over the network, the attack vector is inferred to be remote, likely through the management interface, with no additional prerequisites mentioned in the advisory.

Generated by OpenCVE AI on August 5, 2026 at 20:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the iLO 6 firmware to at least version 1.78 to eliminate the vulnerability.
  • Restrict network access to the iLO interface by limiting connections to trusted management networks or VPNs.
  • Monitor iLO performance metrics and set alerts for abnormal load indicative of DoS attacks.

Generated by OpenCVE AI on August 5, 2026 at 20:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Hpe
Hpe hpe Integrated Lights-out 6
Vendors & Products Hpe
Hpe hpe Integrated Lights-out 6

Wed, 05 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title Denial of Service in HPE iLO 6 Firmware < 1.78

Wed, 05 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Description A potential denial of service vulnerability exists in HPE Integrated Lights-Out 6 (iLO 6) prior to v1.78.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Hpe Hpe Integrated Lights-out 6 Integrated Lights-out 6 Integrated Lights-out 6 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-08-06T13:19:37.261Z

Reserved: 2026-07-16T19:47:44.513Z

Link: CVE-2026-63457

cve-icon Vulnrichment

Updated: 2026-08-05T19:07:03.664Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-05T19:17:31.703

Modified: 2026-08-10T17:44:23.177

Link: CVE-2026-63457

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T10:05:13Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption