Local Data Modification and Disclosure Vulnerability in HPE Integrated Lights-Out 5 Firmware
CVE-2022-28633
7.3HIGH
Summary
A vulnerability was identified in HPE Integrated Lights-Out 5 (iLO 5) firmware versions prior to 2.71, allowing an unprivileged user to exploit local access. This flaw enables attackers to read and write to the iLO 5 firmware file system, leading to a complete loss of confidentiality and a partial loss of integrity and availability of the system. HPE has issued a firmware update to address this critical issue and mitigate the associated risks.
Affected Version(s)
HPE Integrated Lights-Out 5 (iLO 5) Prior to 2.71
References
CVSS V3.1
Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved