Lucene search

K
cvelistHpeCVELIST:CVE-2022-23701
HistoryFeb 24, 2022 - 9:05 p.m.

CVE-2022-23701

2022-02-2421:05:21
hpe
www.cve.org

5.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

31.3%

A potential remote host header injection security vulnerability has been identified in HPE Integrated Lights-Out 4 (iLO 4) firmware version(s): Prior to 2.60. This vulnerability could be remotely exploited to allow an attacker to supply invalid input to the iLO 4 webserver, causing it to respond with a redirect to an attacker-controlled domain. HPE has provided a firmware update to resolve this vulnerability in HPE Integrated Lights-Out 4 (iLO 4).

CNA Affected

[
  {
    "product": "HPE Integrated Lights-Out 4 (iLO 4)",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Prior to 2.60"
      }
    ]
  }
]

5.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

31.3%

Related for CVELIST:CVE-2022-23701