Resource exhaustion in HPE Integrated Lights-Out 5 (iLO 5), and HPE Integrated Lights-Out 6 (iLO 6)



| Updated: 2025-04-17
Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2023-30911
CWE-ID CWE-400
Exploitation vector Network
Public exploit N/A
Vulnerable software
HPE ProLiant DL380a Gen11
Hardware solutions / Firmware

HPE Alletra 4140
Hardware solutions / Firmware

HPE Alletra 4120
Hardware solutions / Firmware

HPE Alletra 4110
Hardware solutions / Firmware

HPE Synergy 480 Gen11 Compute Module
Hardware solutions / Firmware

HPE ProLiant ML30 Gen11
Hardware solutions / Firmware

HPE ProLiant DL20 Gen11
Hardware solutions / Firmware

HPE ProLiant DL110 Gen11
Hardware solutions / Firmware

HPE ProLiant DL560 Gen11
Hardware solutions / Firmware

HPE ProLiant ML110 Gen11
Hardware solutions / Firmware

HPE ProLiant RL300 Gen11
Hardware solutions / Firmware

HPE ProLiant DL325 Gen11 Server
Hardware solutions / Firmware

HPE ProLiant DL345 Gen11 Server
Hardware solutions / Firmware

HPE ProLiant DL385 Gen11 Server
Hardware solutions / Firmware

HPE ProLiant DL365 Gen11 Server
Hardware solutions / Firmware

HPE ProLiant DL320 Gen11 Server
Hardware solutions / Firmware

HPE ProLiant ML350 Gen11 Server
Hardware solutions / Firmware

HPE ProLiant DL360 Gen11 Server
Hardware solutions / Firmware

HPE ProLiant DL380 Gen11 Server
Hardware solutions / Firmware

HPE ProLiant m750 Server Blade
Hardware solutions / Firmware

HPE Edgeline e920t Server Blade
Hardware solutions / Firmware

HPE Edgeline e920d Server Blade
Hardware solutions / Firmware

HPE Edgeline e920 Server Blade
Hardware solutions / Firmware

HPE ProLiant e910t Server Blade
Hardware solutions / Firmware

HPE ProLiant e910 Server Blade
Hardware solutions / Firmware

HPE Synergy 480 Gen10 Compute Module
Hardware solutions / Firmware

HPE Synergy 660 Gen10 Compute Module
Hardware solutions / Firmware

HPE Apollo 2000 System
Hardware solutions / Firmware

HPE Apollo 4200 Gen10 Server
Hardware solutions / Firmware

HPE Apollo 4200 Gen10 Plus System
Hardware solutions / Firmware

HPE Apollo 4510 Gen10 System
Hardware solutions / Firmware

HPE Apollo 6500 Gen10 System
Hardware solutions / Firmware

HPE Apollo 6500 Gen10 Plus System
Hardware solutions / Firmware

HPE Apollo n2600 Gen10 Plus
Hardware solutions / Firmware

HPE Apollo n2800 Gen10 Plus
Hardware solutions / Firmware

HPE Apollo r2200 Gen10 12 LFF Configure-to-order Chassis
Hardware solutions / Firmware

HPE Apollo r2600 Gen10 24 SFF Premium Configure-to-order Chassis
Hardware solutions / Firmware

HPE Apollo r2800 Gen10 24 SFF Flexible Configure-to-order Chassis
Hardware solutions / Firmware

HPE ProLiant XL925g Gen10 Plus 1U 4-node Configure-to-order Server
Hardware solutions / Firmware

HPE ProLiant DL110 Gen10 Plus Telco server
Hardware solutions / Firmware

HPE ProLiant MicroServer Gen10 Plus v2
Hardware solutions / Firmware

HPE ProLiant MicroServer Gen10 Plus
Hardware solutions / Firmware

HPE ProLiant XL170r Gen10 Server
Hardware solutions / Firmware

HPE ProLiant XL190r Gen10 Server
Hardware solutions / Firmware

HPE ProLiant XL220n Gen10 Plus Server
Hardware solutions / Firmware

HPE ProLiant XL225n Gen10 Plus 1U Node
Hardware solutions / Firmware

HPE ProLiant XL230k Gen10 Server
Hardware solutions / Firmware

HPE ProLiant XL2x260w Gen10 Server
Hardware solutions / Firmware

HPE ProLiant XL270d Gen10 Server
Hardware solutions / Firmware

HPE ProLiant XL290n Gen10 Plus Server
Hardware solutions / Firmware

HPE ProLiant XL645d Gen10 Plus Server
Hardware solutions / Firmware

HPE ProLiant XL675d Gen10 Plus Server
Hardware solutions / Firmware

HPE ProLiant ML30 Gen10 Server
Hardware solutions / Firmware

HPE ProLiant ML30 Gen10 Plus server
Hardware solutions / Firmware

HPE ProLiant ML110 Gen10 Server
Hardware solutions / Firmware

HPE ProLiant ML350 Gen10 Server
Hardware solutions / Firmware

HPE ProLiant DL20 Gen10 Server
Hardware solutions / Firmware

HPE ProLiant DL20 Gen10 Plus server
Hardware solutions / Firmware

HPE ProLiant DL160 Gen10 Server
Hardware solutions / Firmware

HPE ProLiant DL180 Gen10 Server
Hardware solutions / Firmware

HPE ProLiant DL325 Gen10 Plus v2 server
Hardware solutions / Firmware

HPE ProLiant DL325 Gen10 Plus server
Hardware solutions / Firmware

HPE ProLiant DL345 Gen10 Plus server
Hardware solutions / Firmware

HPE ProLiant DL360 Gen10 Server
Hardware solutions / Firmware

HPE ProLiant DL360 Gen10 Plus server
Hardware solutions / Firmware

HPE ProLiant DL365 Gen10 Plus server
Hardware solutions / Firmware

HPE ProLiant DL380 Gen10 Plus server
Hardware solutions / Firmware

HPE ProLiant DL380 Gen10 Server
Hardware solutions / Firmware

HPE ProLiant DL385 Gen10 Server
Hardware solutions / Firmware

HPE ProLiant DL385 Gen10 Plus v2 server
Hardware solutions / Firmware

HPE ProLiant DL385 Gen10 Plus server
Hardware solutions / Firmware

HPE ProLiant DL560 Gen10 Server
Hardware solutions / Firmware

HPE ProLiant DL580 Gen10 Server
Hardware solutions / Firmware

HPE ProLiant BL460c Gen10 Server Blade
Hardware solutions / Firmware

HPE Integrated Lights-Out 5 (iLO 5)
Hardware solutions / Firmware

HPE Integrated Lights-Out 6 (iLO 6)
Hardware solutions / Firmware

HPE Synergy 480 Gen10 Plus Compute Module
Other software / Other software solutions

Vendor HPE

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Resource exhaustion

EUVDB-ID: #VU107585

Risk: Low

CVSSv4.0: 4.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2023-30911

CWE-ID: CWE-400 - Resource exhaustion

Exploit availability: No

Description

The vulnerability allows a remote privileged user to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources. A remote privileged user can trigger resource exhaustion and perform a denial of service (DoS) attack.

Mitigation

Install update from vendor's website.

Vulnerable software versions

HPE ProLiant DL380a Gen11: before 1.53

HPE Alletra 4140: before 1.53

HPE Alletra 4120: before 1.53

HPE Alletra 4110: before 1.53

HPE Synergy 480 Gen11 Compute Module: before 1.53

HPE ProLiant ML30 Gen11: before 1.53

HPE ProLiant DL20 Gen11: before 1.53

HPE ProLiant DL110 Gen11: before 1.53

HPE ProLiant DL560 Gen11: before 1.53

HPE ProLiant ML110 Gen11: before 1.53

HPE ProLiant RL300 Gen11: before 1.53

HPE ProLiant DL325 Gen11 Server: before 1.53

HPE ProLiant DL345 Gen11 Server: before 1.53

HPE ProLiant DL385 Gen11 Server: before 1.53

HPE ProLiant DL365 Gen11 Server: before 1.53

HPE ProLiant DL320 Gen11 Server: before 1.53

HPE ProLiant ML350 Gen11 Server: before 1.53

HPE ProLiant DL360 Gen11 Server: before 1.53

HPE ProLiant DL380 Gen11 Server: before 1.53

HPE ProLiant m750 Server Blade: before 2.98

HPE Edgeline e920t Server Blade: before 2.98

HPE Edgeline e920d Server Blade: before 2.98

HPE Edgeline e920 Server Blade: before 2.98

HPE ProLiant e910t Server Blade: before 2.98

HPE ProLiant e910 Server Blade: before 2.98

HPE Synergy 480 Gen10 Plus Compute Module: before 2.98

HPE Synergy 480 Gen10 Compute Module: before 2.98

HPE Synergy 660 Gen10 Compute Module: before 2.98

HPE Apollo 2000 System: before 2.98

HPE Apollo 4200 Gen10 Server: before 2.98

HPE Apollo 4200 Gen10 Plus System: before 2.98

HPE Apollo 4510 Gen10 System: before 2.98

HPE Apollo 6500 Gen10 System: before 2.98

HPE Apollo 6500 Gen10 Plus System: before 2.98

HPE Apollo n2600 Gen10 Plus: before 2.98

HPE Apollo n2800 Gen10 Plus: before 2.98

HPE Apollo r2200 Gen10 12 LFF Configure-to-order Chassis: before 2.98

HPE Apollo r2600 Gen10 24 SFF Premium Configure-to-order Chassis: before 2.98

HPE Apollo r2800 Gen10 24 SFF Flexible Configure-to-order Chassis: before 2.98

HPE ProLiant XL925g Gen10 Plus 1U 4-node Configure-to-order Server: before 2.98

HPE ProLiant DL110 Gen10 Plus Telco server: before 2.98

HPE ProLiant MicroServer Gen10 Plus v2: before 2.98

HPE ProLiant MicroServer Gen10 Plus: before 2.98

HPE ProLiant XL170r Gen10 Server: before 2.98

HPE ProLiant XL190r Gen10 Server: before 2.98

HPE ProLiant XL220n Gen10 Plus Server: before 2.98

HPE ProLiant XL225n Gen10 Plus 1U Node: before 2.98

HPE ProLiant XL230k Gen10 Server: before 2.98

HPE ProLiant XL2x260w Gen10 Server: before 2.98

HPE ProLiant XL270d Gen10 Server: before 2.98

HPE ProLiant XL290n Gen10 Plus Server: before 2.98

HPE ProLiant XL645d Gen10 Plus Server: before 2.98

HPE ProLiant XL675d Gen10 Plus Server: before 2.98

HPE ProLiant ML30 Gen10 Server: before 2.98

HPE ProLiant ML30 Gen10 Plus server: before 2.98

HPE ProLiant ML110 Gen10 Server: before 2.98

HPE ProLiant ML350 Gen10 Server: before 2.98

HPE ProLiant DL20 Gen10 Server: before 2.98

HPE ProLiant DL20 Gen10 Plus server: before 2.98

HPE ProLiant DL160 Gen10 Server: before 2.98

HPE ProLiant DL180 Gen10 Server: before 2.98

HPE ProLiant DL325 Gen10 Plus v2 server: before 2.98

HPE ProLiant DL325 Gen10 Plus server: before 2.98

HPE ProLiant DL345 Gen10 Plus server: before 2.98

HPE ProLiant DL360 Gen10 Server: before 2.98

HPE ProLiant DL360 Gen10 Plus server: before 2.98

HPE ProLiant DL365 Gen10 Plus server: before 2.98

HPE ProLiant DL380 Gen10 Plus server: before 2.98

HPE ProLiant DL380 Gen10 Server: before 2.98

HPE ProLiant DL385 Gen10 Server: before 2.98

HPE ProLiant DL385 Gen10 Plus v2 server: before 2.98

HPE ProLiant DL385 Gen10 Plus server: before 2.98

HPE ProLiant DL560 Gen10 Server: before 2.98

HPE ProLiant DL580 Gen10 Server: before 2.98

HPE ProLiant BL460c Gen10 Server Blade: before 2.98

HPE Integrated Lights-Out 5 (iLO 5): before 2.98

HPE Integrated Lights-Out 6 (iLO 6): before 1.53

CPE2.3 External links

https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbhf04544en_us


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###