PT-2022-19116 · Hewlett Packard · Hpe Integrated Lights-Out 5+1

Published

2022-07-28

·

Updated

2022-08-16

·

CVE-2022-28628

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HPE Integrated Lights-Out 5 (iLO 5) versions prior to 2.71
Description A local arbitrary code execution issue was discovered, allowing an unprivileged user to execute arbitrary code, resulting in a complete loss of confidentiality, integrity, and availability. This could lead to sensitive information disclosure, denial of service, and unauthorized data modification.
Recommendations For versions prior to 2.71, update the firmware to resolve this issue. As a temporary workaround, consider restricting access to the firmware until a patch is available.

Fix

Related Identifiers

CVE-2022-28628

Affected Products

Hpe Integrated Lights-Out 5
Hpe Ilo