CVE-2022-28627: High severity hp integrated lights-out 5 vulnerability
A local arbitrary code execution vulnerability was discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71. An unprivileged user could locally exploit this vulnerability to execute arbitrary code resulting in a complete loss of confidentiality, integrity, and availability. HPE has provided a firmware update to resolve this vulnerability in HPE Integrated Lights-Out 5 (iLO 5).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-28627?
CVE-2022-28627 is classified as a critical local arbitrary code execution vulnerability.
How do I fix CVE-2022-28627?
To fix CVE-2022-28627, upgrade the HPE Integrated Lights-Out 5 firmware to version 2.71 or later.
Who is affected by CVE-2022-28627?
CVE-2022-28627 affects unprivileged users of HPE Integrated Lights-Out 5 firmware versions prior to 2.71.
What are the risks associated with CVE-2022-28627?
The risks associated with CVE-2022-28627 include a complete loss of confidentiality, integrity, and availability.
How can CVE-2022-28627 be exploited?
CVE-2022-28627 can be exploited locally by an unprivileged user to execute arbitrary code.