Path Traversal Vulnerability in HPE Cloudline Servers
CVE-2021-25125
Key Information:
- Vendor
HP
- Vendor
- CVE Published:
- 29 January 2021
What is CVE-2021-25125?
A path traversal vulnerability exists in the Baseboard Management Controller (BMC) of specific HPE Cloudline servers. This flaw arises from improper validation in the spx_restservice delsolrecordedvideo_func function, which could allow attackers with local access to gain unauthorized file access outside of designated directories on the affected BMC firmware. This vulnerability could lead to the exposure or alteration of sensitive system files.
Affected Version(s)
HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server Version. 1.09.0.0
HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server Version 1.07.0.0
HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server Version 1.10.0.0