PT-2022-19117 · Hewlett Packard · Hpe Integrated Lights-Out 5+1

Published

2022-07-28

·

Updated

2022-08-16

·

CVE-2022-28629

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HPE Integrated Lights-Out 5 (iLO 5) versions prior to 2.71
Description A local arbitrary code execution issue was discovered, allowing a low privileged user to execute arbitrary code, resulting in a complete loss of confidentiality, integrity, and availability. This could lead to sensitive information disclosure, denial of service, and unauthorized data modification.
Recommendations For versions prior to 2.71, update the firmware to the latest version to resolve the issue. As a temporary workaround, consider restricting access to the firmware until a patch is applied.

Fix

Related Identifiers

CVE-2022-28629

Affected Products

Hpe Integrated Lights-Out 5
Hpe Ilo