Path Traversal Vulnerability in HPE Cloudline Servers
CVE-2021-25128
Key Information:
- Vendor
HP
- Vendor
- CVE Published:
- 29 January 2021
What is CVE-2021-25128?
A path traversal vulnerability exists in the Baseboard Management Controller (BMC) firmware of several HPE Cloudline servers. This flaw allows attackers with local access to bypass restrictions and access unauthorized files on the system. Specifically, the issue lies within the spx_restservice's gethelpdata_func function, which improperly validates input, thereby enabling potential exploitation. Organizations utilizing affected server models should prioritize updates and security assessments to mitigate associated risks.
Affected Version(s)
HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server Version. 1.09.0.0
HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server Version 1.07.0.0
HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server Version 1.10.0.0