Local Information Disclosure and Code Execution in HPE Integrated Lights-Out 5
CVE-2022-28638
7.8HIGH
Key Information:
- Vendor
HP
- Vendor
- CVE Published:
- 20 September 2022
What is CVE-2022-28638?
A vulnerability has been identified in the HPE Integrated Lights-Out 5 (iLO 5) that allows for isolated local information disclosure and arbitrary code execution. This concern arises from the potential impact on confidentiality, integrity, and availability of system resources. Hewlett Packard Enterprise has released updated firmware to mitigate these security risks. It is essential for users to update to the latest version to protect against potential unauthorized access and exploitation.
Affected Version(s)
HPE Integrated Lights-Out 5 (iLO 5) Prior to 2.72
HPE Integrated Lights-Out 5 (iLO 5) = unspecified