PT-2022-19119 · Hewlett Packard · Hpe Integrated Lights-Out 5+1

Published

2022-07-28

·

Updated

2022-08-16

·

CVE-2022-28630

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions HPE Integrated Lights-Out 5 (iLO 5) versions prior to 2.71
Description A local arbitrary code execution issue was discovered, allowing an unprivileged user to execute arbitrary code, resulting in a complete loss of confidentiality and integrity, and a partial loss of availability. User interaction is required to exploit this issue. Additionally, multiple local and adjacent security issues have been identified, which could potentially result in arbitrary code execution, denial of service (DoS), sensitive information disclosure, and unauthorized data modification.
Recommendations For versions prior to 2.71, update the firmware to the latest version provided by HPE to resolve the issue. As a temporary workaround, consider restricting user interaction with the vulnerable firmware until a patch is applied.

Fix

Related Identifiers

CVE-2022-28630

Affected Products

Hpe Integrated Lights-Out 5
Hpe Ilo