Remote Host Header Injection in HPE Integrated Lights-Out 4 Firmware
CVE-2022-23701
Key Information:
- Vendor
HP
- Vendor
- CVE Published:
- 24 February 2022
What is CVE-2022-23701?
A significant security vulnerability exists in the HPE Integrated Lights-Out 4 (iLO 4) firmware allowing for potential remote host header injection. Attackers could exploit this flaw by sending malicious input to the iLO 4 webserver, which may inadvertently lead to an unauthorized redirect to a domain controlled by the attacker. HPE has addressed this issue with a firmware update, and users are strongly advised to upgrade to at least version 2.60 to mitigate the risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
HPE Integrated Lights-Out 4 (iLO 4) Prior to 2.60
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved