Local Buffer Overflow in HPE Cloudline Server BMC Firmware
CVE-2021-25130

7.8HIGH

What is CVE-2021-25130?

The Baseboard Management Controller (BMC) in several HPE Cloudline servers is subject to a local buffer overflow vulnerability. This issue occurs within the spx_restservice setactdir_func function, potentially allowing an attacker with local access to the system to execute arbitrary code. Proper code execution could lead to unauthorized control over specific functionalities on the affected server models. Users of the impacted servers should assess their systems and apply any available patches or mitigation strategies to secure their infrastructure.

Affected Version(s)

HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server Version. 1.09.0.0

HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server Version 1.07.0.0

HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server Version 1.10.0.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.