Local Code Execution Vulnerability in HPE Integrated Lights-Out 5 Firmware
CVE-2022-28627
8.4HIGH
Summary
A local arbitrary code execution vulnerability has been identified in firmware versions prior to 2.71 of the HPE Integrated Lights-Out 5 (iLO 5). This flaw allows an unprivileged user to exploit the system locally, potentially executing arbitrary code which leads to a significant compromise of confidentiality, integrity, and availability. HPE has released a firmware update to address this issue, urging users to apply the update to safeguard their systems.
Affected Version(s)
HPE Integrated Lights-Out 5 (iLO 5) Prior to 2.71
References
CVSS V3.1
Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved