CVE-2022-23701

MEDIUM

HPE Integrated Lights-Out 4 < 2.60 - Remote Host Header Injection

Title source: llm
STIX 2.1

Description

A potential remote host header injection security vulnerability has been identified in HPE Integrated Lights-Out 4 (iLO 4) firmware version(s): Prior to 2.60. This vulnerability could be remotely exploited to allow an attacker to supply invalid input to the iLO 4 webserver, causing it to respond with a redirect to an attacker-controlled domain. HPE has provided a firmware update to resolve this vulnerability in HPE Integrated Lights-Out 4 (iLO 4).

References (1)

Core 1

Scores

CVSS v3 5.3
EPSS 0.0031
EPSS Percentile 54.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-74
Status published
Products (1)
hpe/integrated_lights-out < 2.60
Published Feb 24, 2022
Tracked Since Feb 18, 2026