Description
A remote user validation failure vulnerability exists in HPE Integrated Lights-Out (iLO) 7 firmware.
Published: 2026-10-05
Score: 9 Critical
EPSS: n/a
KEV: No
Impact: Remote Authentication Bypass
Action: Immediate Patch
AI Analysis

Impact

A flaw in the HPE Integrated Lights-Out (iLO) 7 firmware allows a remote user to bypass validation checks, effectively gaining unauthorized access to management functions that should be protected by authentication. The weakness stems from an improper authentication process, enabling attackers to execute privileged operations without valid credentials. As a result, the confidentiality, integrity, and availability of the managed hardware could be compromised.

Affected Systems

The vulnerability affects Hewlett Packard Enterprise’s Integrated Lights-Out (iLO) version 7 firmware. No specific revision numbers are listed, so all iLO 7 deployments without the patch are potentially impacted.

Risk and Exploitability

The CVSS score of 9 indicates a high severity impact with network reachability. Although EPSS data is not available, the lack of a KEV listing does not mitigate the high risk profile. The attack vector is remote; an attacker only needs network access to the iLO interface and can exploit the validation failure without interacting with the host operating system. Given the critical nature of iLO management functions, the potential for full system compromise is significant.

Generated by OpenCVE AI on October 5, 2026 at 16:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest HPE iLO firmware update that addresses the authentication bypass flaw.
  • If the patch cannot be applied immediately, restrict external network access to the iLO interface using firewall rules or network segmentation to limit potential attack traffic.
  • Configure iLO to enforce authentication for all management operations and verify that no unauthenticated endpoints remain open.
  • Enable and review audit logging to detect any unauthorized access attempts to the iLO system.

Generated by OpenCVE AI on October 5, 2026 at 16:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 16:45:00 +0000

Type Values Removed Values Added
Title Remote Validation Failure in HPE Integrated Lights-Out (iLO) 7 Firmware
Weaknesses CWE-284

Mon, 05 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 15:00:00 +0000

Type Values Removed Values Added
Description A remote user validation failure vulnerability exists in HPE Integrated Lights-Out (iLO) 7 firmware.
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-10-05T15:19:09.406Z

Reserved: 2026-08-25T14:46:40.580Z

Link: CVE-2026-79820

cve-icon Vulnrichment

Updated: 2026-10-05T15:18:22.698Z

cve-icon NVD

Status : Received

Published: 2026-10-05T15:17:22.290

Modified: 2026-10-05T16:17:16.563

Link: CVE-2026-79820

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T16:30:20Z

Weaknesses