Local Code Execution Vulnerability in HPE Integrated Lights-Out 5 Firmware
CVE-2022-28627

8.4HIGH

Key Information:

Vendor
HP
Vendor
CVE Published:
12 August 2022

Summary

A local arbitrary code execution vulnerability has been identified in firmware versions prior to 2.71 of the HPE Integrated Lights-Out 5 (iLO 5). This flaw allows an unprivileged user to exploit the system locally, potentially executing arbitrary code which leads to a significant compromise of confidentiality, integrity, and availability. HPE has released a firmware update to address this issue, urging users to apply the update to safeguard their systems.

Affected Version(s)

HPE Integrated Lights-Out 5 (iLO 5) Prior to 2.71

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.