Local Code Execution Vulnerability in HPE Integrated Lights-Out 5 Firmware
CVE-2022-28626

6.7MEDIUM

Key Information:

Vendor
HP
Vendor
CVE Published:
12 August 2022

Summary

A local arbitrary code execution vulnerability has been identified in HPE Integrated Lights-Out 5 (iLO 5) firmware versions prior to 2.71. This vulnerability allows a highly privileged user to execute arbitrary code on the device, compromising the confidentiality, integrity, and availability of the system. HPE has issued a firmware update to mitigate this risk and safeguard users from potential exploitation.

Affected Version(s)

HPE Integrated Lights-Out 5 (iLO 5) Prior to 2.71

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.