CVE-2022-28629: High severity hp integrated lights-out 5 vulnerability
A local arbitrary code execution vulnerability was discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71. A low privileged user could locally exploit this vulnerability to execute arbitrary code resulting in a complete loss of confidentiality, integrity, and availability. HPE has provided a firmware update to resolve this vulnerability in HPE Integrated Lights-Out 5 (iLO 5).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-28629?
CVE-2022-28629 is a local arbitrary code execution vulnerability in HPE Integrated Lights-Out 5 (iLO 5) firmware versions prior to 2.71.
How severe is CVE-2022-28629?
CVE-2022-28629 has a severity rating of 7.8, classified as high.
How can the vulnerability CVE-2022-28629 be exploited?
A low privileged user could locally exploit CVE-2022-28629 to execute arbitrary code, resulting in a complete loss of confidentiality, integrity, and availability.
Which software versions are affected by CVE-2022-28629?
HPE Integrated Lights-Out 5 (iLO 5) firmware versions prior to 2.71 are affected by CVE-2022-28629.
Where can I find more information about CVE-2022-28629?
For more information about CVE-2022-28629, you can visit the reference provided by HPE: https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf04333en_us.