Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-28636


A potential local arbitrary code execution and a local denial of service (DoS) vulnerability within an isolated process were discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71. An unprivileged user could locally exploit this vulnerability to potentially execute arbitrary code in an isolated process resulting in a complete loss of confidentiality, integrity, and availability within that process. In addition, an unprivileged user could exploit a denial of service (DoS) vulnerability in an isolated process resulting in a complete loss of availability within that process. A successful attack depends on conditions beyond the attackers control. HPE has provided a firmware update to resolve this vulnerability in HPE Integrated Lights-Out 5 (iLO 5).


Published

2022-08-12T15:15:14.467

Last Modified

2024-11-21T06:57:37.667

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.4 (HIGH)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System hpe integrated_lights-out_5_firmware < 2.71 Yes
Hardware hpe apollo_2000_gen10_plus_system - No
Hardware hpe apollo_4200_gen10_server - No
Hardware hpe apollo_4510_gen10_system - No
Hardware hpe apollo_6500_gen10_plus_system - No
Hardware hpe apollo_6500_gen10_system - No
Hardware hpe apollo_n2600_gen10_plus - No
Hardware hpe apollo_n2800_gen10_plus - No
Hardware hpe apollo_r2600_gen10 - No
Hardware hpe apollo_r2800_gen10 - No
Hardware hpe edgeline_e920_server_blade - No
Hardware hpe edgeline_e920d_server_blade - No
Hardware hpe edgeline_e920t_server_blade - No
Hardware hpe proliant_bl460c_gen10_server_blade - No
Hardware hpe proliant_dl110_gen10_plus_telco_server - No
Hardware hpe proliant_dl120_gen10_server - No
Hardware hpe proliant_dl160_gen10_server - No
Hardware hpe proliant_dl180_gen10_server - No
Hardware hpe proliant_dl20_gen10_plus_server - No
Hardware hpe proliant_dl20_gen10_server - No
Hardware hpe proliant_dl325_gen10_plus_server - No
Hardware hpe proliant_dl325_gen10_plus_v2_server - No
Hardware hpe proliant_dl325_gen10_server - No
Hardware hpe proliant_dl345_gen10_plus_server - No
Hardware hpe proliant_dl360_gen10_plus_server - No
Hardware hpe proliant_dl360_gen10_server - No
Hardware hpe proliant_dl365_gen10_plus_server - No
Hardware hpe proliant_dl380_gen10_plus_server - No
Hardware hpe proliant_dl380_gen10_server - No
Hardware hpe proliant_dl385_gen10_plus_server - No
Hardware hpe proliant_dl385_gen10_plus_v2_server - No
Hardware hpe proliant_dl385_gen10_server - No
Hardware hpe proliant_dl560_gen10_server - No
Hardware hpe proliant_dl580_gen10_server - No
Hardware hpe proliant_dx170r_gen10_server - No
Hardware hpe proliant_dx190r_gen10_server - No
Hardware hpe proliant_dx220n_gen10_plus_server - No
Hardware hpe proliant_dx325_gen10_plus_v2_server - No
Hardware hpe proliant_dx360_gen10_plus_server - No
Hardware hpe proliant_dx360_gen10_server - No
Hardware hpe proliant_dx380_gen10_plus_server - No
Hardware hpe proliant_dx380_gen10_server - No
Hardware hpe proliant_dx385_gen10_plus_server - No
Hardware hpe proliant_dx385_gen10_plus_v2_server - No
Hardware hpe proliant_dx4200_gen10_server - No
Hardware hpe proliant_dx560_gen10_server - No
Hardware hpe proliant_e910_server_blade - No
Hardware hpe proliant_e910t_server_blade - No
Hardware hpe proliant_m750_server_blade - No
Hardware hpe proliant_microserver_gen10_plus - No
Hardware hpe proliant_ml110_gen10_server - No
Hardware hpe proliant_ml30_gen10_plus_server - No
Hardware hpe proliant_ml30_gen10_server - No
Hardware hpe proliant_ml350_gen10_server - No
Hardware hpe proliant_xl170r_gen10_server - No
Hardware hpe proliant_xl190r_gen10_server - No
Hardware hpe proliant_xl220n_gen10_plus_server - No
Hardware hpe proliant_xl225n_gen10_plus_1u_node - No
Hardware hpe proliant_xl230k_gen10_server - No
Hardware hpe proliant_xl270d_gen10_server - No
Hardware hpe proliant_xl290n_gen10_plus_server - No
Hardware hpe proliant_xl420_gen10_server - No
Hardware hpe proliant_xl450_gen10_server - No
Hardware hpe proliant_xl645d_gen10_plus_server - No
Hardware hpe proliant_xl675d_gen10_plus_server - No
Hardware hpe proliant_xl925g_gen10_plus_server - No
Hardware hpe storage_file_controller - No
Hardware hpe storage_performance_file_controller - No
Hardware hpe storeeasy_1460_storage - No
Hardware hpe storeeasy_1560_storage - No
Hardware hpe storeeasy_1660_expanded_storage - No
Hardware hpe storeeasy_1660_performance_storage - No
Hardware hpe storeeasy_1660_storage - No
Hardware hpe storeeasy_1860_performance_storage - No
Hardware hpe storeeasy_1860_storage - No

References