Remote Cross Site Scripting Vulnerability in HPE iLO 3 and HPE iLO 4
CVE-2016-4406
Key Information:
- Vendor
HP
- Vendor
- CVE Published:
- 6 August 2018
What is CVE-2016-4406?
A remote cross site scripting vulnerability allows attackers to inject malicious scripts into web pages viewed by users. This can lead to unauthorized actions taken on behalf of unsuspecting users or the exposure of sensitive information. Affected systems include HPE iLO 3 and HPE iLO 4, which require updates to mitigate this risk. Users are advised to upgrade to versions v1.88 and v2.44 respectively to ensure they are protected against potential exploits.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
HP Integrated Lights-Out 3 (iLO 3), HPE Integrated Lights-Out 4 (iLO 4) iLO 3 all version prior to v1.88,iLO 4 all versions prior to v2.44
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved