CVE-2023-28083
published 2023-03-22CVE-2023-28083: A remote Cross-site Scripting vulnerability was discovered in HPE Integrated Lights-Out 6 (iLO 6), Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 4…
PriorityP422medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.45%
35.9th percentile
A remote Cross-site Scripting vulnerability was discovered in HPE Integrated Lights-Out 6 (iLO 6), Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 4 (iLO 4). HPE has provided software updates to resolve this vulnerability in HPE Integrated Lights-Out.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hp | integrated_lights-out_4 | < 2.82 | 2.82 |
| hp | integrated_lights-out_5 | < 2.78 | 2.78 |
| hp | integrated_lights-out_6 | < 1.20 | 1.20 |
| hpe | integrated_lights-out | >= Integrated Lights-Out 4 (iLO 4) < 2.82 | 2.82 |
| hpe | integrated_lights-out | >= Integrated Lights-Out 5 (iLO 5) < 2.78 | 2.78 |
| hpe | integrated_lights-out | >= Integrated Lights-Out 6 (iLO 6) < 1.20 | 1.20 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-03-22
Published