Hpe Integrated Lights-Out vulnerabilities
2 known vulnerabilities affecting hpe/integrated_lights-out.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2023-28083MEDIUMCVSS 5.4≥ Integrated Lights-Out 6 (iLO 6), < 1.20≥ Integrated Lights-Out 5 (iLO 5) , < 2.78+1 more2023-03-22
CVE-2023-28083 [HIGH] CWE-79 CVE-2023-28083: A remote Cross-site Scripting vulnerability was discovered in HPE Integrated Lights-Out 6 (iLO 6), I
A remote Cross-site Scripting vulnerability was discovered in HPE Integrated Lights-Out 6 (iLO 6), Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 4 (iLO 4). HPE has provided software updates to resolve this vulnerability in HPE Integrated Lights-Out.
cvelistv5nvd
CVE-2022-23701MEDIUMCVSS 5.3fixed in 2.602022-02-24
CVE-2022-23701 [MEDIUM] CWE-74 CVE-2022-23701: A potential remote host header injection security vulnerability has been identified in HPE Integrate
A potential remote host header injection security vulnerability has been identified in HPE Integrated Lights-Out 4 (iLO 4) firmware version(s): Prior to 2.60. This vulnerability could be remotely exploited to allow an attacker to supply invalid input to the iLO 4 webserver, causing it to respond with a redirect to an attacker-controlled domain. HPE h
nvd