CVE-2026-63457: Vulnerability in Hewlett Packard Enterprise (HPE) HPE Integrated Lights-Out 6 (iLO 6)
A denial of service vulnerability exists in Hewlett Packard Enterprise Integrated Lights-Out 6 (iLO 6) firmware versions prior to 1.78. This issue could allow an attacker to disrupt availability without requiring privileges or user interaction. The vulnerability has a medium severity rating with a CVSS score of 6.5. No official patch or remediation guidance has been provided yet by the vendor.
AI Analysis
Technical Summary
CVE-2026-63457 identifies a denial of service vulnerability in HPE Integrated Lights-Out 6 (iLO 6) firmware versions before 1.78. The flaw is categorized under CWE-400 (Uncontrolled Resource Consumption), indicating that it may allow an attacker to exhaust resources and cause service disruption. The vulnerability does not impact confidentiality or integrity but affects availability. The CVSS 3.1 vector indicates the attack requires adjacent network access, no privileges, and no user interaction. As of the published date, no vendor advisory or patch has been released.
Potential Impact
The vulnerability can cause denial of service, impacting the availability of the iLO 6 management interface. There is no impact on confidentiality or integrity. Exploitation does not require privileges or user interaction but requires network adjacency. No known exploits are reported in the wild.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, monitor vendor communications for updates. No specific mitigations have been provided by HPE at this time.
CVE-2026-63457: Vulnerability in Hewlett Packard Enterprise (HPE) HPE Integrated Lights-Out 6 (iLO 6)
Description
A denial of service vulnerability exists in Hewlett Packard Enterprise Integrated Lights-Out 6 (iLO 6) firmware versions prior to 1.78. This issue could allow an attacker to disrupt availability without requiring privileges or user interaction. The vulnerability has a medium severity rating with a CVSS score of 6.5. No official patch or remediation guidance has been provided yet by the vendor.
CVSS v3.1
Score 6.5medium
Affected software
Hewlett Packard Enterprise (HPE)
HPE Integrated Lights-Out 6 (iLO 6)
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-63457 identifies a denial of service vulnerability in HPE Integrated Lights-Out 6 (iLO 6) firmware versions before 1.78. The flaw is categorized under CWE-400 (Uncontrolled Resource Consumption), indicating that it may allow an attacker to exhaust resources and cause service disruption. The vulnerability does not impact confidentiality or integrity but affects availability. The CVSS 3.1 vector indicates the attack requires adjacent network access, no privileges, and no user interaction. As of the published date, no vendor advisory or patch has been released.
Potential Impact
The vulnerability can cause denial of service, impacting the availability of the iLO 6 management interface. There is no impact on confidentiality or integrity. Exploitation does not require privileges or user interaction but requires network adjacency. No known exploits are reported in the wild.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, monitor vendor communications for updates. No specific mitigations have been provided by HPE at this time.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- hpe
- Date Reserved
- 2026-07-16T19:47:44.513Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a738076bf8831d53945c674
Added to database: 08/05/2026, 18:27:02 UTC
Last enriched: 08/13/2026, 17:32:07 UTC
Last updated: 09/17/2026, 22:01:37 UTC
Views: 46
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.