Arbitrary Code Execution and DoS Vulnerability in HPE Integrated Lights-Out 5 Firmware
CVE-2022-28631
8.8HIGH
Summary
A vulnerability exists within HPE Integrated Lights-Out 5 (iLO 5) firmware that allows an unprivileged user on an adjacent network to exploit an isolated process. This could result in arbitrary code execution, potentially compromising the confidentiality, integrity, and availability of the process. Additionally, the vulnerability allows a denial of service (DoS), leading to a complete loss of availability within that process. HPE has released a firmware update to address these critical security concerns.
Affected Version(s)
HPE Integrated Lights-Out 5 (iLO 5) Prior to 2.71
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved