CVE-2023-28083
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
22/03/2023
Last modified:
24/03/2023
Description
A remote Cross-site Scripting vulnerability was discovered in HPE Integrated Lights-Out 6 (iLO 6), Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 4 (iLO 4). HPE has provided software updates to resolve this vulnerability in HPE Integrated Lights-Out.
Impact
Base Score 3.x
5.40
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:hp:integrated_lights-out_4:*:*:*:*:*:*:*:* | 2.82 (excluding) | |
| cpe:2.3:h:hpe:apollo_4200_gen9_server:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hpe:apollo_r2000_chassis:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hpe:proliant_bl420c_gen8_server:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hpe:proliant_bl460c_gen8_server_blade:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hpe:proliant_bl460c_gen9_server_blade:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hpe:proliant_bl465c_gen8_server_blade:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hpe:proliant_bl660c_gen8_server_blade:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hpe:proliant_bl660c_gen9_server:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hpe:proliant_dl120_gen9_server:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hpe:proliant_dl160_gen8_server:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hpe:proliant_dl160_gen9_server:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hpe:proliant_dl180_gen9_server:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hpe:proliant_dl20_gen9_server:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hpe:proliant_dl320e_gen8_server:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



