HIGH · 8.3

CVE-2023-28083

A remote Cross-site Scripting vulnerability was discovered in HPE Integrated Lights-Out 6 (iLO 6), Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 4 (iLO 4). HPE has provided software update...

Vulnerability Description

A remote Cross-site Scripting vulnerability was discovered in HPE Integrated Lights-Out 6 (iLO 6), Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 4 (iLO 4). HPE has provided software updates to resolve this vulnerability in HPE Integrated Lights-Out.

CVSS Score

8.3

HIGH

CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
LOW

Affected Products

VendorProductVersions
HpIntegrated Lights-Out 4< 2.82
HpeApollo 4200 Gen9 Server-
HpeApollo R2000 Chassis-
HpeProliant Bl420C Gen8 Server-
HpeProliant Bl460C Gen8 Server Blade-
HpeProliant Bl460C Gen9 Server Blade-
HpeProliant Bl465C Gen8 Server Blade-
HpeProliant Bl660C Gen8 Server Blade-
HpeProliant Bl660C Gen9 Server-
HpeProliant Dl120 Gen9 Server-
HpeProliant Dl160 Gen8 Server-
HpeProliant Dl160 Gen9 Server-
HpeProliant Dl180 Gen9 Server-
HpeProliant Dl20 Gen9 Server-
HpeProliant Dl320E Gen8 Server-
HpeProliant Dl320E Gen8 V2 Server-
HpeProliant Dl360 Gen9 Server-
HpeProliant Dl360E Gen8 Server-
HpeProliant Dl360P Gen8 Server-
HpeProliant Dl380 Gen9 Server-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-28083?

CVE-2023-28083 is a vulnerability with a CVSS score of 8.3 (HIGH). A remote Cross-site Scripting vulnerability was discovered in HPE Integrated Lights-Out 6 (iLO 6), Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 4 (iLO 4). HPE has provided software update...

How severe is CVE-2023-28083?

CVE-2023-28083 has been rated HIGH with a CVSS base score of 8.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-28083?

Check the references section above for vendor advisories and patch information. Affected products include: Hp Integrated Lights-Out 4, Hpe Apollo 4200 Gen9 Server, Hpe Apollo R2000 Chassis, Hpe Proliant Bl420C Gen8 Server, Hpe Proliant Bl460C Gen8 Server Blade.