CVE-2022-28634

Summary

CVECVE-2022-28634
StatePUBLIC
Assigner[email protected]
Source PriorityCVE Program / NVD first with legacy fallback
Published2022-08-12 15:15:00 UTC
Updated2022-08-16 14:24:00 UTC
DescriptionA local arbitrary code execution vulnerability was discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71. A highly privileged user could locally exploit this vulnerability to execute arbitrary code resulting in a complete loss of confidentiality, integrity, and availability. HPE has provided a firmware update to resolve this vulnerability in HPE Integrated Lights-Out 5 (iLO 5).

Risk And Classification

Problem Types: NVD-CWE-noinfo

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Hardware Hpe Apollo 2000 Gen10 Plus System - All All All
Hardware Hpe Apollo 4200 Gen10 Server - All All All
Hardware Hpe Apollo 4510 Gen10 System - All All All
Hardware Hpe Apollo 6500 Gen10 Plus System - All All All
Hardware Hpe Apollo 6500 Gen10 System - All All All
Hardware Hpe Apollo N2600 Gen10 Plus - All All All
Hardware Hpe Apollo N2800 Gen10 Plus - All All All
Hardware Hpe Apollo R2600 Gen10 - All All All
Hardware Hpe Apollo R2800 Gen10 - All All All
Hardware Hpe Edgeline E920d Server Blade - All All All
Hardware Hpe Edgeline E920t Server Blade - All All All
Hardware Hpe Edgeline E920 Server Blade - All All All
Operating System Hpe Integrated Lights-out 5 Firmware All All All All
Hardware Hpe Proliant Bl460c Gen10 Server Blade - All All All
Hardware Hpe Proliant Dl110 Gen10 Plus Telco Server - All All All
Hardware Hpe Proliant Dl120 Gen10 Server - All All All
Hardware Hpe Proliant Dl160 Gen10 Server - All All All
Hardware Hpe Proliant Dl180 Gen10 Server - All All All
Hardware Hpe Proliant Dl20 Gen10 Plus Server - All All All
Hardware Hpe Proliant Dl20 Gen10 Server - All All All
Hardware Hpe Proliant Dl325 Gen10 Plus Server - All All All
Hardware Hpe Proliant Dl325 Gen10 Plus V2 Server - All All All
Hardware Hpe Proliant Dl325 Gen10 Server - All All All
Hardware Hpe Proliant Dl345 Gen10 Plus Server - All All All
Hardware Hpe Proliant Dl360 Gen10 Plus Server - All All All
Hardware Hpe Proliant Dl360 Gen10 Server - All All All
Hardware Hpe Proliant Dl365 Gen10 Plus Server - All All All
Hardware Hpe Proliant Dl380 Gen10 Plus Server - All All All
Hardware Hpe Proliant Dl380 Gen10 Server - All All All
Hardware Hpe Proliant Dl385 Gen10 Plus Server - All All All
Hardware Hpe Proliant Dl385 Gen10 Plus V2 Server - All All All
Hardware Hpe Proliant Dl385 Gen10 Server - All All All
Hardware Hpe Proliant Dl560 Gen10 Server - All All All
Hardware Hpe Proliant Dl580 Gen10 Server - All All All
Hardware Hpe Proliant Dx170r Gen10 Server - All All All
Hardware Hpe Proliant Dx190r Gen10 Server - All All All
Hardware Hpe Proliant Dx220n Gen10 Plus Server - All All All
Hardware Hpe Proliant Dx325 Gen10 Plus V2 Server - All All All
Hardware Hpe Proliant Dx360 Gen10 Plus Server - All All All
Hardware Hpe Proliant Dx360 Gen10 Server - All All All
Hardware Hpe Proliant Dx380 Gen10 Plus Server - All All All
Hardware Hpe Proliant Dx380 Gen10 Server - All All All
Hardware Hpe Proliant Dx385 Gen10 Plus Server - All All All
Hardware Hpe Proliant Dx385 Gen10 Plus V2 Server - All All All
Hardware Hpe Proliant Dx4200 Gen10 Server - All All All
Hardware Hpe Proliant Dx560 Gen10 Server - All All All
Hardware Hpe Proliant E910t Server Blade - All All All
Hardware Hpe Proliant E910 Server Blade - All All All
Hardware Hpe Proliant M750 Server Blade - All All All
Hardware Hpe Proliant Microserver Gen10 Plus - All All All
Hardware Hpe Proliant Ml110 Gen10 Server - All All All
Hardware Hpe Proliant Ml30 Gen10 Plus Server - All All All
Hardware Hpe Proliant Ml30 Gen10 Server - All All All
Hardware Hpe Proliant Ml350 Gen10 Server - All All All
Hardware Hpe Proliant Xl170r Gen10 Server - All All All
Hardware Hpe Proliant Xl190r Gen10 Server - All All All
Hardware Hpe Proliant Xl220n Gen10 Plus Server - All All All
Hardware Hpe Proliant Xl225n Gen10 Plus 1u Node - All All All
Hardware Hpe Proliant Xl230k Gen10 Server - All All All
Hardware Hpe Proliant Xl270d Gen10 Server - All All All
Hardware Hpe Proliant Xl290n Gen10 Plus Server - All All All
Hardware Hpe Proliant Xl420 Gen10 Server - All All All
Hardware Hpe Proliant Xl450 Gen10 Server - All All All
Hardware Hpe Proliant Xl645d Gen10 Plus Server - All All All
Hardware Hpe Proliant Xl675d Gen10 Plus Server - All All All
Hardware Hpe Proliant Xl925g Gen10 Plus Server - All All All
Hardware Hpe Storage File Controller - All All All
Hardware Hpe Storage Performance File Controller - All All All
Hardware Hpe Storeeasy 1460 Storage - All All All
Hardware Hpe Storeeasy 1560 Storage - All All All
Hardware Hpe Storeeasy 1660 Expanded Storage - All All All
Hardware Hpe Storeeasy 1660 Performance Storage - All All All
Hardware Hpe Storeeasy 1660 Storage - All All All
Hardware Hpe Storeeasy 1860 Performance Storage - All All All
Hardware Hpe Storeeasy 1860 Storage - All All All

References

ReferenceSourceLinkTags
Document Display | HPE Support Center MISC support.hpe.com
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Legacy QID Mappings

  • 730605 Hewlett Packard Enterprise (HPE) Integrated Lights-Out 5 (iLO 5) Multiple Vulnerabilities (HPESBHF04333)
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report