CVE-2022-28631: High severity hp integrated lights-out 5 vulnerability
A potential arbitrary code execution and a denial of service (DoS) vulnerability within an isolated process were discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71. An unprivileged user could exploit this vulnerability in an adjacent network to potentially execute arbitrary code in an isolated process resulting in a complete loss of confidentiality, integrity, and availability within that process. In addition, an unprivileged user could exploit a denial of service (DoS) vulnerability in an isolated process resulting in a complete loss of availability within that process. HPE has provided a firmware update to resolve this vulnerability in HPE Integrated Lights-Out 5 (iLO 5).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-28631?
The severity of CVE-2022-28631 is high due to the potential for arbitrary code execution and denial of service (DoS).
How do I fix CVE-2022-28631?
To fix CVE-2022-28631, update the HPE Integrated Lights-Out 5 firmware to version 2.71 or later.
Who is affected by CVE-2022-28631?
CVE-2022-28631 affects users running HPE Integrated Lights-Out 5 firmware versions prior to 2.71.
What kind of attack can exploit CVE-2022-28631?
CVE-2022-28631 can be exploited by an unprivileged user on an adjacent network to potentially execute arbitrary code.
Is CVE-2022-28631 a local or remote vulnerability?
CVE-2022-28631 is considered a remote vulnerability since it can be exploited from an adjacent network.