Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-28640 | A potential remote host header injection security vulnerability has been identified in HPE Integrated Lights-Out 4 (iLO 4) firmware version(s): Prior to 2.60. This vulnerability could be remotely exploited to allow an attacker to supply invalid input to the iLO 4 webserver, causing it to respond with a redirect to an attacker-controlled domain. HPE has provided a firmware update to resolve this vulnerability in HPE Integrated Lights-Out 4 (iLO 4). |
No history.
Status: PUBLISHED
Assigner: hpe
Published:
Updated: 2024-08-03T03:51:45.987Z
Reserved: 2022-01-19T00:00:00.000Z
Link: CVE-2022-23701
No data.
Status : Modified
Published: 2022-02-24T22:15:08.393
Modified: 2026-06-17T04:30:39.957
Link: CVE-2022-23701
No data.
OpenCVE Enrichment
No data.
-
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
EUVD