CVE-2022-28634: Medium severity hp integrated lights-out 5 vulnerability
A local arbitrary code execution vulnerability was discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71. A highly privileged user could locally exploit this vulnerability to execute arbitrary code resulting in a complete loss of confidentiality, integrity, and availability. HPE has provided a firmware update to resolve this vulnerability in HPE Integrated Lights-Out 5 (iLO 5).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-28634?
The severity of CVE-2022-28634 is critical due to its potential for arbitrary code execution.
How do I fix CVE-2022-28634?
To fix CVE-2022-28634, upgrade HPE Integrated Lights-Out 5 firmware to version 2.71 or later.
Who is affected by CVE-2022-28634?
CVE-2022-28634 affects HPE Integrated Lights-Out 5 firmware versions prior to 2.71.
What are the potential impacts of CVE-2022-28634?
The potential impacts of CVE-2022-28634 include a complete loss of confidentiality, integrity, and availability of the affected system.
How does CVE-2022-28634 work?
CVE-2022-28634 allows a highly privileged user to locally exploit the vulnerability to execute arbitrary code.