PT-2022-19119 · Hewlett Packard · Hpe Integrated Lights-Out 5+1
Published
2022-07-28
·
Updated
2022-08-16
·
CVE-2022-28630
CVSS v3.1
7.3
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
HPE Integrated Lights-Out 5 (iLO 5) versions prior to 2.71
Description
A local arbitrary code execution issue was discovered, allowing an unprivileged user to execute arbitrary code, resulting in a complete loss of confidentiality and integrity, and a partial loss of availability. User interaction is required to exploit this issue. Additionally, multiple local and adjacent security issues have been identified, which could potentially result in arbitrary code execution, denial of service (DoS), sensitive information disclosure, and unauthorized data modification.
Recommendations
For versions prior to 2.71, update the firmware to the latest version provided by HPE to resolve the issue. As a temporary workaround, consider restricting user interaction with the vulnerable firmware until a patch is applied.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hpe Integrated Lights-Out 5
Hpe Ilo