A potential remote host header injection security vulnerability has been identified in HPE Integrated Lights-Out 4 (iLO 4) firmware version(s): Prior to 2.60. This vulnerability could be remotely exploited to allow an attacker to supply invalid input to the iLO 4 webserver, causing it to respond with a redirect to an attacker-controlled domain. HPE has provided a firmware update to resolve this vulnerability in HPE Integrated Lights-Out 4 (iLO 4).
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: hpe
Published: 2022-02-24T21:05:21
Updated: 2024-08-03T03:51:45.987Z
Reserved: 2022-01-19T00:00:00
Link: CVE-2022-23701
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-02-24T22:15:08.393
Modified: 2024-11-21T06:49:08.177
Link: CVE-2022-23701
Redhat
No data.