First published: Wed Mar 22 2023(Updated: )
A remote Cross-site Scripting vulnerability was discovered in HPE Integrated Lights-Out 6 (iLO 6), Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 4 (iLO 4). HPE has provided software updates to resolve this vulnerability in HPE Integrated Lights-Out.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
HP Integrated Lights-Out 4 Firmware | <2.82 | |
HPE Apollo 4200 Gen9 Server | ||
HPE Apollo R2000 Chassis | ||
HP ProLiant BL420c Gen8 Server | ||
HPE ProLiant BL460c Gen8 Blade Server | ||
HP ProLiant BL460c Gen9 Server Blade | ||
HP ProLiant BL465c Gen8 (AMD) | ||
HPE ProLiant bl660c Gen8 Blade Server | ||
HPE ProLiant BL660c Gen9 Server Firmware | ||
HPE ProLiant DL120 Gen9 Server | ||
HP ProLiant DL160 Gen8 Server | ||
HP ProLiant DL160 Gen9 Server | ||
HP ProLiant DL180 Gen9 Server | ||
HP ProLiant DL20 Gen9 Server Firmware | ||
HPE ProLiant DL320e Gen8 v2 Server | ||
HP ProLiant DL320e Gen8 v2 Server Firmware | ||
HP ProLiant DL360 Gen9 Server | ||
HPE ProLiant DL360e Gen8 Server | ||
HPE ProLiant DL360p Gen8 Server | ||
HP ProLiant DL380 Gen9 Server Firmware | ||
HP ProLiant DL380e Gen8 Server | ||
HPE ProLiant DL380p Gen8 Server | ||
HPE ProLiant DL385p Gen8 (AMD) Firmware | ||
HP ProLiant DL560 Gen8 Server Firmware | ||
HPE ProLiant DL560 Gen9 Server | ||
HP ProLiant DL580 Gen8 Server | ||
HPE ProLiant DL580 Gen9 Server | ||
HP ProLiant DL60 Gen9 Server | ||
HPE ProLiant DL80 Gen9 Server | ||
HPE ProLiant MicroServer Gen8 | ||
HPE ProLiant ml110 gen9 server | ||
HP ProLiant ML30 Gen9 Server | ||
HPE ProLiant ML310e Gen8 v2 Server | ||
HP ProLiant ML310e Gen8 v2 Server Firmware | ||
HP ProLiant ML350 Gen9 Server | ||
HP ProLiant ML350e Gen8 Server | ||
HPE ProLiant ML350e Gen8 v2 Server Firmware | ||
HP ProLiant ML350p Gen8 Server Firmware | ||
HPE ProLiant SL210t Gen8 Server | ||
HPE ProLiant sl230s gen8 server | ||
HPE ProLiant SL250s Gen8 Server | ||
HPE ProLiant SL270s Gen8 Server | ||
HPE ProLiant SL270s Gen8 Server Firmware | ||
HPE ProLiant WS460c Gen8 Graphics Server Blade | ||
HPE ProLiant WS460c Gen9 Graphics Server Blade | ||
HP ProLiant XL170R Gen9 | ||
HP ProLiant XL190r Gen9 Server Firmware | ||
HPE ProLiant XL220a Gen8 v2 Server | ||
HPE ProLiant XL230a Gen9 Server Firmware | ||
HPE ProLiant XL230b Gen9 Server | ||
HPE ProLiant XL250a Gen9 Server Firmware | ||
HP ProLiant XL270d Gen9 Server | ||
HPE ProLiant XL450 Gen9 Server | ||
HPE ProLiant xl730f Gen9 Server | ||
HP ProLiant XL740f Gen9 Server | ||
HP ProLiant XL750f Gen9 Server | ||
HPE StoreEasy 1430 Storage | ||
HPE StoreEasy 1440 Storage | ||
HPE StoreEasy 1450 Storage | ||
HPE StoreEasy 1530 Storage | ||
HPE StoreEasy 1540 Storage | ||
HPE StoreEasy 1550 Storage | ||
HPE StoreEasy 1630 Storage | ||
HPE StoreEasy 1640 Storage | ||
HPE StoreEasy 1650 Expanded Storage | ||
HPE StoreEasy 1650 Expanded Storage | ||
HPE StoreEasy 1830 Storage | ||
HPE StoreEasy 1840 Storage | ||
HPE StoreEasy 1850 Storage | ||
HPE StoreEasy 3830 Gateway Storage Blade | ||
HPE StoreEasy 3830 Gateway Storage Blade | ||
HPE storeeasy 3840 gateway storage | ||
HPE StoreEasy 3840 Gateway Storage Blade | ||
HPE StoreEasy 3850 Gateway | ||
HPE StoreEasy 3850 Gateway | ||
HPE StoreEasy 3850 Gateway Storage | ||
HPE StoreVirtual 3000 File Controller | ||
HPE Synergy 480 Gen9 | ||
HPE Synergy 620 Gen9 | ||
HPE Synergy 660 Gen9 | ||
HPE Synergy 680 Gen9 | ||
HPE Integrated Lights-Out 5 firmware | <2.78 | |
HPE Apollo 4200 Gen10 Plus System | ||
HPE Apollo 4200 Gen10 Plus System | ||
HP Apollo 4510 System | ||
HPE Apollo 6500 Gen10 Plus | ||
HPE Apollo 6500 Gen10 Plus | ||
HPE Apollo n2600 Gen10 Plus | ||
HPE Apollo n2800 Gen10 Plus | ||
HPE Apollo r2200 Gen10 | ||
HPE Apollo R2600 Gen10 | ||
HPE Apollo r2800 Gen10 | ||
HPE Edgeline E920 Server Blade | ||
HPE Edgeline E920d Server Blade | ||
HPE Edgeline E920t Server Blade | ||
HPE ProLiant BL460c Gen10 Server Blade | ||
HP ProLiant DL120 Gen10 Server | ||
HP ProLiant DL160 Gen10 Server | ||
HPE ProLiant DL180 Gen10 Server | ||
HPE ProLiant DL20 Gen10 Plus Server | ||
HPE ProLiant DL20 Gen10 Plus Server | ||
HPE ProLiant DL325 Gen10 Plus Server | ||
HPE ProLiant DL325 Gen10 Server | ||
HPE ProLiant DL345 Gen10 Plus Server | ||
HPE ProLiant DL360 Gen10 Plus Server | ||
HP ProLiant DL360 Gen10 | ||
HPE ProLiant DL365 Gen10 Plus Server | ||
HPE ProLiant DL380 Gen10 Plus Server | ||
HP ProLiant DL380 Gen10 | ||
HPE ProLiant DX385 Gen10 Plus Server | ||
HPE ProLiant DL385 Gen10 Plus v2 Server | ||
HPE ProLiant DL385 Gen10 Server | ||
HPE proliant dl560 gen10 server | ||
HPE ProLiant DL580 Gen10 Server Firmware | ||
HPE ProLiant DX170R Gen10 Server | ||
HPE ProLiant DX190R Gen10 Server | ||
HPE ProLiant DX220N Gen10 Plus Server | ||
HPE ProLiant DX325 Gen10 Plus v2 Server | ||
HPE ProLiant DX360 Gen10 Plus Server | ||
HPE ProLiant DX360 Gen10 Server | ||
HPE ProLiant DX380 Gen10 Plus Server | ||
HPE ProLiant DX380 Gen10 Server | ||
HPE ProLiant DX385 Gen10 Plus Server | ||
HPE ProLiant DX385 Gen10 Plus v2 Server | ||
HPE ProLiant DX4200 Gen10 Server | ||
HPE ProLiant DX560 Gen10 Server | ||
HPE ProLiant E910 Server Blade | ||
HPE ProLiant E910T Server Blade | ||
HP ProLiant ML110 Gen10 Server | ||
HPE ProLiant ML30 Gen10 Plus Server | ||
HP ProLiant ML350 Gen10 Server | ||
HP ProLiant xl170r Gen10 | ||
HP ProLiant xl190r Gen10 | ||
HPE ProLiant XL220n Gen10 Plus Server | ||
HPE ProLiant XL225N Gen10 Plus 1U Node | ||
HP ProLiant XL230k Gen10 Server | ||
HPE ProLiant XL270d Gen10 Server | ||
HPE ProLiant XL290n Gen10 Plus Server | ||
HPE ProLiant XL450 Gen10 Server Firmware | ||
HPE ProLiant XL645D Gen10 Plus Server | ||
HPE ProLiant XL675d Gen10 Plus Server | ||
HPE Storage File Controller | ||
HPE Storage Performance File Controller | ||
HPE StoreEasy 1460 Storage | ||
HPE StoreEasy 1560 Storage | ||
HPE StoreEasy 1660 Expanded Storage | ||
HPE storeeasy 1660 performance storage | ||
HPE StoreEasy 1660 Expanded Storage | ||
HPE StoreEasy 1860 Performance Storage | ||
HPE StoreEasy 1860 Performance Storage | ||
HPE Synergy 480 Gen10 Plus Compute Module | ||
HPE Synergy 480 Gen10 Plus Compute Module | ||
HP Synergy 660 Gen10 Firmware | ||
HPE Integrated Lights-Out 6 | <1.20 | |
HPE ProLiant DL320 Gen11 Server | ||
HPE ProLiant DL325 Gen11 Server | ||
HPE ProLiant DL345 Gen11 Server | ||
HPE ProLiant DL360 Gen11 Server | ||
HPE ProLiant DL365 Gen11 Server | ||
HPE ProLiant DL380 Gen11 Server | ||
HPE ProLiant DL385 Gen11 Server | ||
HPE ProLiant ML350 Gen11 Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-28083 is considered high due to its potential for remote exploitation via cross-site scripting.
To fix CVE-2023-28083, you should immediately apply the latest software updates provided by HPE for Integrated Lights-Out 4, 5, and 6.
CVE-2023-28083 affects HPE Integrated Lights-Out 4, 5, and 6, specifically versions prior to 2.82 for iLO 4 and 2.78 for iLO 5, and 1.20 for iLO 6.
Yes, CVE-2023-28083 can be exploited remotely, allowing attackers to execute scripts in the context of the affected user's session.
CVE-2023-28083 impacts HPE Integrated Lights-Out 4, Integrated Lights-Out 5, and Integrated Lights-Out 6 firmware.