Lucene search

K
cve[email protected]CVE-2022-23704
HistoryMay 09, 2022 - 9:15 p.m.

CVE-2022-23704

2022-05-0921:15:08
web.nvd.nist.gov
62
5
ilo 4
cve-2022-23704
remote dos
vulnerability
nvd

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.006 Low

EPSS

Percentile

79.1%

A potential security vulnerability has been identified in Integrated Lights-Out 4 (iLO 4). The vulnerability could allow remote Denial of Service. The vulnerability is resolved in Integrated Lights-Out 4 (iLO 4) 2.80 and later.

Affected configurations

NVD
Node
hpintegrated_lights-out_4Range<2.80
AND
hpeapollo_4200_gen9_serverMatch-
OR
hpeproliant_bl420c_gen8_serverMatch-
OR
hpeproliant_bl460c_gen8_server_bladeMatch-
OR
hpeproliant_bl460c_gen9_server_bladeMatch-
OR
hpeproliant_bl465c_gen8_server_bladeMatch-
OR
hpeproliant_bl660c_gen8_server_bladeMatch-
OR
hpeproliant_bl660c_gen9_serverMatch-
OR
hpeproliant_dl120_gen9_serverMatch-
OR
hpeproliant_dl160_gen8_serverMatch-
OR
hpeproliant_dl160_gen9_serverMatch-
OR
hpeproliant_dl180_gen9_serverMatch-
OR
hpeproliant_dl20_gen9_serverMatch-
OR
hpeproliant_dl320e_gen8_serverMatch-
OR
hpeproliant_dl320e_gen8_v2_serverMatch-
OR
hpeproliant_dl360_gen9_serverMatch-
OR
hpeproliant_dl360e_gen8_serverMatch-
OR
hpeproliant_dl360p_gen8_serverMatch-
OR
hpeproliant_dl380_gen9_serverMatch-
OR
hpeproliant_dl380e_gen8_serverMatch-
OR
hpeproliant_dl380p_gen8_serverMatch-
OR
hpeproliant_dl385p_gen8Match-
OR
hpeproliant_dl560_gen8_serverMatch-
OR
hpeproliant_dl560_gen9_serverMatch-
OR
hpeproliant_dl580_gen8_serverMatch-
OR
hpeproliant_dl580_gen9_serverMatch-
OR
hpeproliant_dl60_gen9_serverMatch-
OR
hpeproliant_dl80_gen9_serverMatch-
OR
hpeproliant_ec200a_serverMatch-
OR
hpeproliant_microserver_gen8Match-
OR
hpeproliant_ml110_gen9_serverMatch-
OR
hpeproliant_ml150_gen9_serverMatch-
OR
hpeproliant_ml30_gen9_serverMatch-
OR
hpeproliant_ml310e_gen8_serverMatch-
OR
hpeproliant_ml310e_gen8_v2_serverMatch-
OR
hpeproliant_ml350_gen9_serverMatch-
OR
hpeproliant_ml350e_gen8_v2_serverMatch-
OR
hpeproliant_ml350p_gen8_serverMatch-
OR
hpeproliant_sl210t_gen8_serverMatch-
OR
hpeproliant_sl230s_gen8_serverMatch-
OR
hpeproliant_sl250s_gen8_serverMatch-
OR
hpeproliant_sl270s_gen8_se_serverMatch-
OR
hpeproliant_sl270s_gen8_serverMatch-
OR
hpeproliant_sl4540_gen8_1_node_serverMatch-
OR
hpeproliant_ws460c_gen8_graphics_server_bladeMatch-
OR
hpeproliant_ws460c_gen9_graphics_server_bladeMatch-
OR
hpeproliant_xl170r_gen9_serverMatch-
OR
hpeproliant_xl190r_gen9_serverMatch-
OR
hpeproliant_xl220a_gen8_v2_serverMatch-
OR
hpeproliant_xl230a_gen9_serverMatch-
OR
hpeproliant_xl250a_gen9_serverMatch-
OR
hpeproliant_xl450_gen9_serverMatch-
OR
hpeproliant_xl730f_gen9_serverMatch-
OR
hpeproliant_xl740f_gen9_serverMatch-
OR
hpeproliant_xl750f_gen9_serverMatch-
OR
hpesynergy_480_gen9_compute_moduleMatch-
OR
hpesynergy_620_gen9_compute_moduleMatch-
OR
hpesynergy_660_gen9_compute_moduleMatch-
OR
hpesynergy_680_gen9_compute_moduleMatch-

CNA Affected

[
  {
    "product": "HPE Integrated Lights-Out 4 (iLO 4)",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Prior to iLO 4 version 2.80"
      }
    ]
  }
]

Social References

More

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.006 Low

EPSS

Percentile

79.1%

Related for CVE-2022-23704