Description
A potential local adjacent arbitrary code execution vulnerability that could potentially lead to a loss of confidentiality, integrity, and availability was discovered in HPE Integrated Lights-Out 5 (iLO 5) in Version: 2.71. Hewlett Packard Enterprise has provided updated firmware for HPE Integrated Lights-Out 5 (iLO 5) that addresses this security vulnerability.
Published: 2022-09-20
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-33082 A potential local adjacent arbitrary code execution vulnerability that could potentially lead to a loss of confidentiality, integrity, and availability was discovered in HPE Integrated Lights-Out 5 (iLO 5) in Version: 2.71. Hewlett Packard Enterprise has provided updated firmware for HPE Integrated Lights-Out 5 (iLO 5) that addresses this security vulnerability.
History

Wed, 28 May 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Hp Apollo 4200 Gen10 Server Apollo 4500 Apollo R2000 Chassis
Hpe Apollo 2000 Gen10 Plus System Apollo 4200 Gen10 Plus System Apollo 4510 Gen10 System Apollo 6500 Gen10 Plus Apollo N2600 Gen10 Plus Apollo N2800 Gen10 Plus Apollo R2600 Gen10 Apollo R2800 Gen10 Edgeline E920 Server Blade Edgeline E920d Server Blade Edgeline E920t Server Blade Integrated Lights-out 5 Integrated Lights-out 5 Firmware Proliant Bl460c Gen10 Server Blade Proliant Dl110 Gen10 Plus Telco Server Proliant Dl160 Gen10 Server Proliant Dl180 Gen10 Server Proliant Dl20 Gen10 Plus Server Proliant Dl20 Gen10 Server Proliant Dl325 Gen10 Plus Server Proliant Dl325 Gen10 Plus V2 Server Proliant Dl325 Gen10 Server Proliant Dl345 Gen10 Plus Server Proliant Dl360 Gen10 Plus Server Proliant Dl360 Gen10 Server Proliant Dl365 Gen10 Plus Server Proliant Dl380 Gen10 Plus Server Proliant Dl380 Gen10 Server Proliant Dl385 Gen10 Plus Server Proliant Dl385 Gen10 Plus V2 Server Proliant Dl385 Gen10 Server Proliant Dl560 Gen10 Server Proliant Dl580 Gen10 Server Proliant Dx170r Gen10 Server Proliant Dx190r Gen10 Server Proliant Dx220n Gen10 Plus Server Proliant Dx325 Gen10 Plus V2 Server Proliant Dx360 Gen10 Plus Server Proliant Dx360 Gen10 Server Proliant Dx380 Gen10 Plus Server Proliant Dx380 Gen10 Server Proliant Dx385 Gen10 Plus Server Proliant Dx385 Gen10 Plus V2 Server Proliant Dx4200 Gen10 Server Proliant Dx560 Gen10 Server Proliant E910 Server Blade Proliant E910t Server Blade Proliant M750 Server Blade Proliant Microserver Gen10 Plus Proliant Ml110 Gen10 Server Proliant Ml30 Gen10 Plus Server Proliant Ml30 Gen10 Server Proliant Ml350 Gen10 Server Proliant Xl170r Gen10 Server Proliant Xl190r Gen10 Server Proliant Xl220n Gen10 Plus Server Proliant Xl225n Gen10 Plus 1u Node Proliant Xl230k Gen10 Server Proliant Xl270d Gen10 Server Proliant Xl290n Gen10 Plus Server Proliant Xl420 Gen10 Server Proliant Xl450 Gen10 Server Proliant Xl645d Gen10 Plus Server Proliant Xl675d Gen10 Plus Server Proliant Xl925g Gen10 Plus 1u 4-node Configure-to-order Server Storage File Controller Storage Performance File Controller Storeeasy 1460 Storage Storeeasy 1560 Storage Storeeasy 1660 Expanded Storage Storeeasy 1660 Performance Storage Storeeasy 1660 Storage Storeeasy 1860 Performance Storage Storeeasy 1860 Storage
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2025-05-28T15:52:55.759Z

Reserved: 2022-04-04T00:00:00.000Z

Link: CVE-2022-28640

cve-icon Vulnrichment

Updated: 2024-08-03T05:56:16.403Z

cve-icon NVD

Status : Modified

Published: 2022-09-20T21:15:10.497

Modified: 2025-05-28T16:15:22.580

Link: CVE-2022-28640

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses