CVE-2022-23701: Medium severity hpe integrated lights-out vulnerability
A potential remote host header injection security vulnerability has been identified in HPE Integrated Lights-Out 4 (iLO 4) firmware version(s): Prior to 2.60. This vulnerability could be remotely exploited to allow an attacker to supply invalid input to the iLO 4 webserver, causing it to respond with a redirect to an attacker-controlled domain. HPE has provided a firmware update to resolve this vulnerability in HPE Integrated Lights-Out 4 (iLO 4).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-23701?
CVE-2022-23701 is considered a potential remote host header injection vulnerability in HPE Integrated Lights-Out 4 firmware.
How do I fix CVE-2022-23701?
To fix CVE-2022-23701, upgrade the HPE Integrated Lights-Out 4 firmware to version 2.60 or later.
What versions of iLO 4 are affected by CVE-2022-23701?
CVE-2022-23701 affects HPE Integrated Lights-Out 4 firmware versions prior to 2.60.
Can CVE-2022-23701 be exploited remotely?
Yes, CVE-2022-23701 can be exploited remotely if the affected iLO 4 firmware is accessible from external networks.
What impact does CVE-2022-23701 have on systems?
The impact of CVE-2022-23701 could allow attackers to supply invalid input to the iLO 4 webserver, potentially leading to unauthorized access or server misbehavior.