cvedb.io
CVE-2022-28630
HIGH · CVSS 7.3
EPSS exploitation probability: 0%
Published 2022-08-12T15:15:14.210 · Last modified 2026-06-17T04:38:44.450

Summary

A local arbitrary code execution vulnerability was discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71. An unprivileged user could locally exploit this vulnerability to execute arbitrary code resulting in a complete loss of confidentiality and integrity, and a partial loss of availability. User interaction is required to exploit this vulnerability. HPE has provided a firmware update to resolve this vulnerability in HPE Integrated Lights-Out 5 (iLO 5).

Affected products

hpe — integrated_lights-out_5_firmware

Does this affect you?

Add your gear to cvedb and we'll alert you only when hpe ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.