Path Traversal Vulnerability in HPE Cloudline Server Firmware
CVE-2021-25129
Key Information:
- Vendor
HP
- Vendor
- CVE Published:
- 29 January 2021
What is CVE-2021-25129?
A path traversal vulnerability exists in the Baseboard Management Controller (BMC) of HPE Cloudline servers. This allows an attacker with local access to manipulate paths to access sensitive data that should be restricted. Affected servers include multiple models from the Cloudline series, posing risks to server integrity and confidentiality if exploited. It is vital for users of these systems to apply necessary patches and updates to mitigate this vulnerability.
Affected Version(s)
HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server Version. 1.09.0.0
HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server Version 1.07.0.0
HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server Version 1.10.0.0