cbcvebase.
CVE-2023-28083
published 2023-03-22

CVE-2023-28083: A remote Cross-site Scripting vulnerability was discovered in HPE Integrated Lights-Out 6 (iLO 6), Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 4…

PriorityP422medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.45%
35.9th percentile
A remote Cross-site Scripting vulnerability was discovered in HPE Integrated Lights-Out 6 (iLO 6), Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 4 (iLO 4). HPE has provided software updates to resolve this vulnerability in HPE Integrated Lights-Out.

Affected

6 ranges
VendorProductVersion rangeFixed in
hpintegrated_lights-out_4< 2.822.82
hpintegrated_lights-out_5< 2.782.78
hpintegrated_lights-out_6< 1.201.20
hpeintegrated_lights-out>= Integrated Lights-Out 4 (iLO 4) < 2.822.82
hpeintegrated_lights-out>= Integrated Lights-Out 5 (iLO 5) < 2.782.78
hpeintegrated_lights-out>= Integrated Lights-Out 6 (iLO 6) < 1.201.20
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.