Arbitrary Code Execution and DoS Vulnerability in HPE Integrated Lights-Out 5 Firmware
CVE-2022-28631

8.8HIGH

Key Information:

Vendor
HP
Vendor
CVE Published:
12 August 2022

Summary

A vulnerability exists within HPE Integrated Lights-Out 5 (iLO 5) firmware that allows an unprivileged user on an adjacent network to exploit an isolated process. This could result in arbitrary code execution, potentially compromising the confidentiality, integrity, and availability of the process. Additionally, the vulnerability allows a denial of service (DoS), leading to a complete loss of availability within that process. HPE has released a firmware update to address these critical security concerns.

Affected Version(s)

HPE Integrated Lights-Out 5 (iLO 5) Prior to 2.71

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.