First published: Thu Feb 24 2022(Updated: )
A potential remote host header injection security vulnerability has been identified in HPE Integrated Lights-Out 4 (iLO 4) firmware version(s): Prior to 2.60. This vulnerability could be remotely exploited to allow an attacker to supply invalid input to the iLO 4 webserver, causing it to respond with a redirect to an attacker-controlled domain. HPE has provided a firmware update to resolve this vulnerability in HPE Integrated Lights-Out 4 (iLO 4).
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
HPE Integrated Lights-Out | <2.60 | |
HP Integrated Lights-Out 4 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-23701 is considered a potential remote host header injection vulnerability in HPE Integrated Lights-Out 4 firmware.
To fix CVE-2022-23701, upgrade the HPE Integrated Lights-Out 4 firmware to version 2.60 or later.
CVE-2022-23701 affects HPE Integrated Lights-Out 4 firmware versions prior to 2.60.
Yes, CVE-2022-23701 can be exploited remotely if the affected iLO 4 firmware is accessible from external networks.
The impact of CVE-2022-23701 could allow attackers to supply invalid input to the iLO 4 webserver, potentially leading to unauthorized access or server misbehavior.