Local Code Execution Vulnerability in HPE Integrated Lights-Out 5 Firmware
CVE-2022-28626
6.7MEDIUM
Summary
A local arbitrary code execution vulnerability has been identified in HPE Integrated Lights-Out 5 (iLO 5) firmware versions prior to 2.71. This vulnerability allows a highly privileged user to execute arbitrary code on the device, compromising the confidentiality, integrity, and availability of the system. HPE has issued a firmware update to mitigate this risk and safeguard users from potential exploitation.
Affected Version(s)
HPE Integrated Lights-Out 5 (iLO 5) Prior to 2.71
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved