CVE-2022-28632: High severity hp integrated lights-out 5 vulnerability
A potential arbitrary code execution and a denial of service (DoS) vulnerability within an isolated process were discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71. An unprivileged user could exploit this vulnerability in an adjacent network to potentially execute arbitrary code in an isolated process resulting in a complete loss of confidentiality, integrity, and availability within that process. In addition, an unprivileged user could exploit a denial of service (DoS) vulnerability in an isolated process resulting in a complete loss of availability within that process. HPE has provided a firmware update to resolve this vulnerability in HPE Integrated Lights-Out 5 (iLO 5).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-28632?
The severity of CVE-2022-28632 is classified as critical due to its potential for arbitrary code execution and denial of service.
How do I fix CVE-2022-28632?
To fix CVE-2022-28632, users should update HPE Integrated Lights-Out 5 firmware to version 2.71 or later.
Who is affected by CVE-2022-28632?
CVE-2022-28632 affects HPE Integrated Lights-Out 5 firmware versions prior to 2.71.
Can an unprivileged user exploit CVE-2022-28632?
Yes, an unprivileged user can exploit CVE-2022-28632 from an adjacent network.
What types of attacks can be executed using CVE-2022-28632?
CVE-2022-28632 can be exploited to achieve arbitrary code execution and potentially cause denial of service.