CVE-2022-28630: High severity hp integrated lights-out 5 vulnerability
A local arbitrary code execution vulnerability was discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71. An unprivileged user could locally exploit this vulnerability to execute arbitrary code resulting in a complete loss of confidentiality and integrity, and a partial loss of availability. User interaction is required to exploit this vulnerability. HPE has provided a firmware update to resolve this vulnerability in HPE Integrated Lights-Out 5 (iLO 5).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-28630?
CVE-2022-28630 is classified as a critical vulnerability due to its potential for local arbitrary code execution.
How do I fix CVE-2022-28630?
To address CVE-2022-28630, upgrade your HPE Integrated Lights-Out 5 firmware to version 2.71 or later.
Who is affected by CVE-2022-28630?
CVE-2022-28630 affects users of HPE Integrated Lights-Out 5 firmware versions prior to 2.71.
What type of vulnerability is CVE-2022-28630?
CVE-2022-28630 is a local arbitrary code execution vulnerability.
Can an unprivileged user exploit CVE-2022-28630?
Yes, an unprivileged user can exploit CVE-2022-28630 to execute arbitrary code.