cvedb.io
CVE-2022-28633
HIGH · CVSS 7.3
EPSS exploitation probability: 0%
Published 2022-08-12T15:15:14.337 · Last modified 2026-06-17T04:38:44.800

Summary

A local disclosure of sensitive information and a local unauthorized data modification vulnerability were discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71. An unprivileged user could locally exploit this vulnerability to read and write to the iLO 5 firmware file system resulting in a complete loss of confidentiality and a partial loss of integrity and availability. HPE has provided a firmware update to resolve this vulnerability in HPE Integrated Lights-Out 5 (iLO 5).

Affected products

hpe — integrated_lights-out_5_firmware

Does this affect you?

Add your gear to cvedb and we'll alert you only when hpe ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.