Vulnerability Description
A local arbitrary code execution vulnerability was discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71. A highly privileged user could locally exploit this vulnerability to execute arbitrary code resulting in a complete loss of confidentiality, integrity, and availability. HPE has provided a firmware update to resolve this vulnerability in HPE Integrated Lights-Out 5 (iLO 5).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hpe | Integrated Lights-Out 5 Firmware | < 2.71 |
| Hpe | Apollo 2000 Gen10 Plus System | - |
| Hpe | Apollo 4200 Gen10 Server | - |
| Hpe | Apollo 4510 Gen10 System | - |
| Hpe | Apollo 6500 Gen10 Plus System | - |
| Hpe | Apollo 6500 Gen10 System | - |
| Hpe | Apollo N2600 Gen10 Plus | - |
| Hpe | Apollo N2800 Gen10 Plus | - |
| Hpe | Apollo R2600 Gen10 | - |
| Hpe | Apollo R2800 Gen10 | - |
| Hpe | Edgeline E920 Server Blade | - |
| Hpe | Edgeline E920D Server Blade | - |
| Hpe | Edgeline E920T Server Blade | - |
| Hpe | Proliant Bl460C Gen10 Server Blade | - |
| Hpe | Proliant Dl110 Gen10 Plus Telco Server | - |
| Hpe | Proliant Dl120 Gen10 Server | - |
| Hpe | Proliant Dl160 Gen10 Server | - |
| Hpe | Proliant Dl180 Gen10 Server | - |
| Hpe | Proliant Dl20 Gen10 Plus Server | - |
| Hpe | Proliant Dl20 Gen10 Server | - |
References
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpeVendor Advisory
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpeVendor Advisory
FAQ
What is CVE-2022-28634?
CVE-2022-28634 is a vulnerability with a CVSS score of 6.7 (MEDIUM). A local arbitrary code execution vulnerability was discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71. A highly privileged user could locally exploit this vulnerabili...
How severe is CVE-2022-28634?
CVE-2022-28634 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-28634?
Check the references section above for vendor advisories and patch information. Affected products include: Hpe Integrated Lights-Out 5 Firmware, Hpe Apollo 2000 Gen10 Plus System, Hpe Apollo 4200 Gen10 Server, Hpe Apollo 4510 Gen10 System, Hpe Apollo 6500 Gen10 Plus System.