Path Traversal Vulnerability in HPE Cloudline Servers
CVE-2021-25124

7.8HIGH

What is CVE-2021-25124?

A local path traversal vulnerability exists in the Baseboard Management Controller (BMC) firmware of multiple HPE Cloudline server models. This flaw allows unauthenticated users to access potentially sensitive files by manipulating file paths, which could lead to unauthorized access to critical system information or files within the server environment. Organizations utilizing these servers should prioritize patching to mitigate risks associated with this vulnerability.

Affected Version(s)

HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server Version. 1.09.0.0

HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server Version 1.07.0.0

HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server Version 1.10.0.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.