8.3

CVE-2023-28083

A remote Cross-site Scripting vulnerability was discovered in HPE Integrated Lights-Out 6 (iLO 6), Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 4 (iLO 4). HPE has provided software updates to resolve this vulnerability in HPE Integrated Lights-Out.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HpIntegrated Lights-out 4 Version < 2.82
   HpeApollo 4200 Gen9 Server Version-
   HpeApollo R2000 Chassis Version-
   HpeProliant Bl420c Gen8 Server Version-
   HpeProliant Bl460c Gen8 Server Blade Version-
   HpeProliant Bl460c Gen9 Server Blade Version-
   HpeProliant Bl465c Gen8 Server Blade Version-
   HpeProliant Bl660c Gen8 Server Blade Version-
   HpeProliant Bl660c Gen9 Server Version-
   HpeProliant Dl120 Gen9 Server Version-
   HpeProliant Dl160 Gen8 Server Version-
   HpeProliant Dl160 Gen9 Server Version-
   HpeProliant Dl180 Gen9 Server Version-
   HpeProliant Dl20 Gen9 Server Version-
   HpeProliant Dl320e Gen8 Server Version-
   HpeProliant Dl320e Gen8 V2 Server Version-
   HpeProliant Dl360 Gen9 Server Version-
   HpeProliant Dl360e Gen8 Server Version-
   HpeProliant Dl360p Gen8 Server Version-
   HpeProliant Dl380 Gen9 Server Version-
   HpeProliant Dl380e Gen8 Server Version-
   HpeProliant Dl380p Gen8 Server Version-
   HpeProliant Dl385p Gen8 (amd) Version-
   HpeProliant Dl560 Gen8 Server Version-
   HpeProliant Dl560 Gen9 Server Version-
   HpeProliant Dl580 Gen8 Server Version-
   HpeProliant Dl580 Gen9 Server Version-
   HpeProliant Dl60 Gen9 Server Version-
   HpeProliant Dl80 Gen9 Server Version-
   HpeProliant Microserver Gen8 Version-
   HpeProliant Ml110 Gen9 Server Version-
   HpeProliant Ml30 Gen9 Server Version-
   HpeProliant Ml310e Gen8 Server Version-
   HpeProliant Ml310e Gen8 V2 Server Version-
   HpeProliant Ml350 Gen9 Server Version-
   HpeProliant Ml350e Gen8 Server Version-
   HpeProliant Ml350e Gen8 V2 Server Version-
   HpeProliant Ml350p Gen8 Server Version-
   HpeProliant Sl210t Gen8 Server Version-
   HpeProliant Sl230s Gen8 Server Version-
   HpeProliant Sl250s Gen8 Server Version-
   HpeProliant Sl270s Gen8 Se Server Version-
   HpeProliant Sl270s Gen8 Server Version-
   HpeProliant Ws460c Gen8 Graphics Server Blade Version-
   HpeProliant Ws460c Gen9 Graphics Server Blade Version-
   HpeProliant Xl170r Gen9 Server Version-
   HpeProliant Xl190r Gen9 Server Version-
   HpeProliant Xl220a Gen8 V2 Server Version-
   HpeProliant Xl230a Gen9 Server Version-
   HpeProliant Xl230b Gen9 Server Version-
   HpeProliant Xl250a Gen9 Server Version-
   HpeProliant Xl270d Gen9 Special Server Version-
   HpeProliant Xl450 Gen9 Server Version-
   HpeProliant Xl730f Gen9 Server Version-
   HpeProliant Xl740f Gen9 Server Version-
   HpeProliant Xl750f Gen9 Server Version-
   HpeStoreeasy 1430 Storage Version-
   HpeStoreeasy 1440 Storage Version-
   HpeStoreeasy 1450 Storage Version-
   HpeStoreeasy 1530 Storage Version-
   HpeStoreeasy 1540 Storage Version-
   HpeStoreeasy 1550 Storage Version-
   HpeStoreeasy 1630 Storage Version-
   HpeStoreeasy 1640 Storage Version-
   HpeStoreeasy 1650 Expanded Storage Version-
   HpeStoreeasy 1650 Storage Version-
   HpeStoreeasy 1830 Storage Version-
   HpeStoreeasy 1840 Storage Version-
   HpeStoreeasy 1850 Storage Version-
   HpeStoreeasy 3830 Gateway Storage Version-
   HpeStoreeasy 3830 Gateway Storage Blade Version-
   HpeStoreeasy 3840 Gateway Storage Version-
   HpeStoreeasy 3840 Gateway Storage Blade Version-
   HpeStoreeasy 3850 Gateway Single Node Upgrade Version-
   HpeStoreeasy 3850 Gateway Storage Version-
   HpeStoreeasy 3850 Gateway Storage Blade Version-
   HpeStorevirtual 3000 File Controller Version-
   HpeSynergy 480 Gen9 Compute Module Version-
   HpeSynergy 620 Gen9 Compute Module Version-
   HpeSynergy 660 Gen9 Compute Module Version-
   HpeSynergy 680 Gen9 Compute Module Version-
HpIntegrated Lights-out 5 Version < 2.78
   HpeApollo 4200 Gen10 Plus System Version-
   HpeApollo 4200 Gen10 Server Version-
   HpeApollo 4510 Gen10 System Version-
   HpeApollo 6500 Gen10 Plus System Version-
   HpeApollo 6500 Gen10 System Version-
   HpeApollo N2600 Gen10 Plus Version-
   HpeApollo N2800 Gen10 Plus Version-
   HpeApollo R2200 Gen10 Version-
   HpeApollo R2600 Gen10 Version-
   HpeApollo R2800 Gen10 Version-
   HpeEdgeline E920 Server Blade Version-
   HpeEdgeline E920d Server Blade Version-
   HpeEdgeline E920t Server Blade Version-
   HpeProliant Bl460c Gen10 Server Blade Version-
   HpeProliant Dl120 Gen10 Server Version-
   HpeProliant Dl160 Gen10 Server Version-
   HpeProliant Dl180 Gen10 Server Version-
   HpeProliant Dl20 Gen10 Plus Server Version-
   HpeProliant Dl20 Gen10 Server Version-
   HpeProliant Dl325 Gen10 Plus Server Version-
   HpeProliant Dl325 Gen10 Server Version-
   HpeProliant Dl345 Gen10 Plus Server Version-
   HpeProliant Dl360 Gen10 Plus Server Version-
   HpeProliant Dl360 Gen10 Server Version-
   HpeProliant Dl365 Gen10 Plus Server Version-
   HpeProliant Dl380 Gen10 Plus Server Version-
   HpeProliant Dl380 Gen10 Server Version-
   HpeProliant Dl385 Gen10 Plus Server Version-
   HpeProliant Dl385 Gen10 Plus V2 Server Version-
   HpeProliant Dl385 Gen10 Server Version-
   HpeProliant Dl560 Gen10 Server Version-
   HpeProliant Dl580 Gen10 Server Version-
   HpeProliant Dx170r Gen10 Server Version-
   HpeProliant Dx190r Gen10 Server Version-
   HpeProliant Dx220n Gen10 Plus Server Version-
   HpeProliant Dx325 Gen10 Plus V2 Server Version-
   HpeProliant Dx360 Gen10 Plus Server Version-
   HpeProliant Dx360 Gen10 Server Version-
   HpeProliant Dx380 Gen10 Plus Server Version-
   HpeProliant Dx380 Gen10 Server Version-
   HpeProliant Dx385 Gen10 Plus Server Version-
   HpeProliant Dx385 Gen10 Plus V2 Server Version-
   HpeProliant Dx4200 Gen10 Server Version-
   HpeProliant Dx560 Gen10 Server Version-
   HpeProliant E910 Server Blade Version-
   HpeProliant E910t Server Blade Version-
   HpeProliant Ml110 Gen10 Server Version-
   HpeProliant Ml30 Gen10 Plus Server Version-
   HpeProliant Ml350 Gen10 Server Version-
   HpeProliant Xl170r Gen10 Server Version-
   HpeProliant Xl190r Gen10 Server Version-
   HpeProliant Xl220n Gen10 Plus Server Version-
   HpeProliant Xl225n Gen10 Plus 1u Node Version-
   HpeProliant Xl230k Gen10 Server Version-
   HpeProliant Xl270d Gen10 Server Version-
   HpeProliant Xl290n Gen10 Plus Server Version-
   HpeProliant Xl450 Gen10 Server Version-
   HpeProliant Xl645d Gen10 Plus Server Version-
   HpeProliant Xl675d Gen10 Plus Server Version-
   HpeStorage File Controller Version-
   HpeStorage Performance File Controller Version-
   HpeStoreeasy 1460 Storage Version-
   HpeStoreeasy 1560 Storage Version-
   HpeStoreeasy 1660 Expanded Storage Version-
   HpeStoreeasy 1660 Performance Storage Version-
   HpeStoreeasy 1660 Storage Version-
   HpeStoreeasy 1860 Performance Storage Version-
   HpeStoreeasy 1860 Storage Version-
   HpeSynergy 480 Gen10 Compute Module Version-
   HpeSynergy 480 Gen10 Plus Compute Module Version-
   HpeSynergy 660 Gen10 Compute Module Version-
HpIntegrated Lights-out 6 Version < 1.20
   HpeProliant Dl320 Gen11 Server Version-
   HpeProliant Dl325 Gen11 Server Version-
   HpeProliant Dl345 Gen11 Server Version-
   HpeProliant Dl360 Gen11 Server Version-
   HpeProliant Dl365 Gen11 Server Version-
   HpeProliant Dl380 Gen11 Server Version-
   HpeProliant Dl385 Gen11 Server Version-
   HpeProliant Ml350 Gen11 Server Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.389
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
security-alert@hpe.com 8.3 1.7 6
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.