CVE-2022-28626: Medium severity hp integrated lights-out 5 vulnerability
A local arbitrary code execution vulnerability was discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71. A highly privileged user could locally exploit this vulnerability to execute arbitrary code resulting in a complete loss of confidentiality, integrity, and availability. HPE has provided a firmware update to resolve this vulnerability in HPE Integrated Lights-Out 5 (iLO 5).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-28626?
CVE-2022-28626 is classified as a local arbitrary code execution vulnerability.
How do I fix CVE-2022-28626?
To fix CVE-2022-28626, update your HPE Integrated Lights-Out 5 firmware to version 2.71 or later.
Who is affected by CVE-2022-28626?
CVE-2022-28626 affects HPE Integrated Lights-Out 5 firmware versions prior to 2.71 used by highly privileged users.
What could happen if CVE-2022-28626 is exploited?
Exploitation of CVE-2022-28626 could lead to a complete loss of confidentiality, integrity, and availability.
Is CVE-2022-28626 a remote exploit?
No, CVE-2022-28626 is a local exploit that requires access by a highly privileged user.