Arbitrary Code Execution and Denial of Service Vulnerability in HPE Integrated Lights-Out 5 Firmware
CVE-2022-28632
8.8HIGH
Summary
A vulnerability has been identified within the firmware of HPE Integrated Lights-Out 5 that allows unprivileged users to exploit arbitrary code execution. This occurs when the firmware is prior to version 2.71, potentially allowing attackers on an adjacent network to execute harmful code, leading to a significant compromise of confidentiality, integrity, and availability in isolation. Furthermore, this vulnerability could facilitate Denial of Service (DoS) attacks, resulting in a complete disruption of service within the isolated processes. HPE has released firmware updates that address these critical security issues.
Affected Version(s)
HPE Integrated Lights-Out 5 (iLO 5) Prior to 2.71
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved