A local arbitrary code execution vulnerability was discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71. A low privileged user could locally exploit this vulnerability to execute arbitrary code resulting in a complete loss of confidentiality, integrity, and availability. HPE has provided a firmware update to resolve this vulnerability in HPE Integrated Lights-Out 5 (iLO 5).
[
{
"product": "HPE Integrated Lights-Out 5 (iLO 5)",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "Prior to 2.71"
}
]
}
]