A remote potential adjacent denial of service (DoS) and potential adjacent arbitrary code execution vulnerability that could potentially lead to a loss of confidentiality, integrity, and availability were discovered in HPE Integrated Lights-Out 5 (iLO 5) in Version: 2.71. Hewlett Packard Enterprise has provided updated firmware for HPE Integrated Lights-Out 5 (iLO 5) that addresses these security vulnerabilities.

Project Subscriptions

Vendors Products
Apollo 4200 Gen10 Server Subscribe
Apollo 4500 Subscribe
Apollo R2000 Chassis Subscribe
Apollo 2000 Gen10 Plus System Subscribe
Apollo 4200 Gen10 Plus System Subscribe
Apollo 4510 Gen10 System Subscribe
Apollo 6500 Gen10 Plus Subscribe
Apollo N2600 Gen10 Plus Subscribe
Apollo N2800 Gen10 Plus Subscribe
Apollo R2600 Gen10 Subscribe
Apollo R2800 Gen10 Subscribe
Edgeline E920 Server Blade Subscribe
Edgeline E920d Server Blade Subscribe
Edgeline E920t Server Blade Subscribe
Integrated Lights-out 5 Subscribe
Integrated Lights-out 5 Firmware Subscribe
Proliant Bl460c Gen10 Server Blade Subscribe
Proliant Dl110 Gen10 Plus Telco Server Subscribe
Proliant Dl160 Gen10 Server Subscribe
Proliant Dl180 Gen10 Server Subscribe
Proliant Dl20 Gen10 Plus Server Subscribe
Proliant Dl20 Gen10 Server Subscribe
Proliant Dl325 Gen10 Plus Server Subscribe
Proliant Dl325 Gen10 Plus V2 Server Subscribe
Proliant Dl325 Gen10 Server Subscribe
Proliant Dl345 Gen10 Plus Server Subscribe
Proliant Dl360 Gen10 Plus Server Subscribe
Proliant Dl360 Gen10 Server Subscribe
Proliant Dl365 Gen10 Plus Server Subscribe
Proliant Dl380 Gen10 Plus Server Subscribe
Proliant Dl380 Gen10 Server Subscribe
Proliant Dl385 Gen10 Plus Server Subscribe
Proliant Dl385 Gen10 Plus V2 Server Subscribe
Proliant Dl385 Gen10 Server Subscribe
Proliant Dl560 Gen10 Server Subscribe
Proliant Dl580 Gen10 Server Subscribe
Proliant Dx170r Gen10 Server Subscribe
Proliant Dx190r Gen10 Server Subscribe
Proliant Dx220n Gen10 Plus Server Subscribe
Proliant Dx325 Gen10 Plus V2 Server Subscribe
Proliant Dx360 Gen10 Plus Server Subscribe
Proliant Dx360 Gen10 Server Subscribe
Proliant Dx380 Gen10 Plus Server Subscribe
Proliant Dx380 Gen10 Server Subscribe
Proliant Dx385 Gen10 Plus Server Subscribe
Proliant Dx385 Gen10 Plus V2 Server Subscribe
Proliant Dx4200 Gen10 Server Subscribe
Proliant Dx560 Gen10 Server Subscribe
Proliant E910 Server Blade Subscribe
Proliant E910t Server Blade Subscribe
Proliant M750 Server Blade Subscribe
Proliant Microserver Gen10 Plus Subscribe
Proliant Ml110 Gen10 Server Subscribe
Proliant Ml30 Gen10 Plus Server Subscribe
Proliant Ml30 Gen10 Server Subscribe
Proliant Ml350 Gen10 Server Subscribe
Proliant Xl170r Gen10 Server Subscribe
Proliant Xl190r Gen10 Server Subscribe
Proliant Xl220n Gen10 Plus Server Subscribe
Proliant Xl225n Gen10 Plus 1u Node Subscribe
Proliant Xl230k Gen10 Server Subscribe
Proliant Xl270d Gen10 Server Subscribe
Proliant Xl290n Gen10 Plus Server Subscribe
Proliant Xl420 Gen10 Server Subscribe
Proliant Xl450 Gen10 Server Subscribe
Proliant Xl645d Gen10 Plus Server Subscribe
Proliant Xl675d Gen10 Plus Server Subscribe
Proliant Xl925g Gen10 Plus 1u 4-node Configure-to-order Server Subscribe
Storage File Controller Subscribe
Storage Performance File Controller Subscribe
Storeeasy 1460 Storage Subscribe
Storeeasy 1560 Storage Subscribe
Storeeasy 1660 Expanded Storage Subscribe
Storeeasy 1660 Performance Storage Subscribe
Storeeasy 1660 Storage Subscribe
Storeeasy 1860 Performance Storage Subscribe
Storeeasy 1860 Storage Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2022-33081 A remote potential adjacent denial of service (DoS) and potential adjacent arbitrary code execution vulnerability that could potentially lead to a loss of confidentiality, integrity, and availability were discovered in HPE Integrated Lights-Out 5 (iLO 5) in Version: 2.71. Hewlett Packard Enterprise has provided updated firmware for HPE Integrated Lights-Out 5 (iLO 5) that addresses these security vulnerabilities.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 29 May 2025 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2025-05-29T13:21:32.356Z

Reserved: 2022-04-04T00:00:00.000Z

Link: CVE-2022-28639

cve-icon Vulnrichment

Updated: 2024-08-03T05:56:16.403Z

cve-icon NVD

Status : Modified

Published: 2022-09-20T21:15:10.457

Modified: 2025-05-29T14:15:28.080

Link: CVE-2022-28639

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses