Vulnerability Description
A remote potential adjacent denial of service (DoS) and potential adjacent arbitrary code execution vulnerability that could potentially lead to a loss of confidentiality, integrity, and availability were discovered in HPE Integrated Lights-Out 5 (iLO 5) in Version: 2.71. Hewlett Packard Enterprise has provided updated firmware for HPE Integrated Lights-Out 5 (iLO 5) that addresses these security vulnerabilities.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hpe | Integrated Lights-Out 5 Firmware | < 2.72 |
| Hp | Apollo 4200 Gen10 Server | - |
| Hp | Apollo 4500 | - |
| Hp | Apollo R2000 Chassis | - |
| Hpe | Apollo 2000 Gen10 Plus System | - |
| Hpe | Apollo 4200 Gen10 Plus System | - |
| Hpe | Apollo 4510 Gen10 System | - |
| Hpe | Apollo 6500 Gen10 Plus | - |
| Hpe | Apollo N2600 Gen10 Plus | - |
| Hpe | Apollo N2800 Gen10 Plus | - |
| Hpe | Apollo R2600 Gen10 | - |
| Hpe | Apollo R2800 Gen10 | - |
| Hpe | Edgeline E920 Server Blade | - |
| Hpe | Edgeline E920D Server Blade | - |
| Hpe | Edgeline E920T Server Blade | - |
| Hpe | Integrated Lights-Out 5 | - |
| Hpe | Proliant Bl460C Gen10 Server Blade | - |
| Hpe | Proliant Dl110 Gen10 Plus Telco Server | - |
| Hpe | Proliant Dl160 Gen10 Server | - |
| Hpe | Proliant Dl180 Gen10 Server | - |
Related Weaknesses (CWE)
References
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpeVendor Advisory
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpeVendor Advisory
FAQ
What is CVE-2022-28639?
CVE-2022-28639 is a vulnerability with a CVSS score of 8.8 (HIGH). A remote potential adjacent denial of service (DoS) and potential adjacent arbitrary code execution vulnerability that could potentially lead to a loss of confidentiality, integrity, and availability ...
How severe is CVE-2022-28639?
CVE-2022-28639 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-28639?
Check the references section above for vendor advisories and patch information. Affected products include: Hpe Integrated Lights-Out 5 Firmware, Hp Apollo 4200 Gen10 Server, Hp Apollo 4500, Hp Apollo R2000 Chassis, Hpe Apollo 2000 Gen10 Plus System.