Local Buffer Overflow in HPE Cloudline Servers' BMC Firmware
CVE-2021-25132
Key Information:
- Vendor
HP
- Vendor
- CVE Published:
- 29 January 2021
What is CVE-2021-25132?
The Baseboard Management Controller (BMC) in several HPE Cloudline server models exhibits a local buffer overflow vulnerability within the spx_restservice setmediaconfig_func function. This flaw can potentially allow an unauthorized local attacker to disrupt the functionality of the BMC, leading to system instability or unauthorized access to sensitive information. Users of the affected HPE Cloudline models are encouraged to implement necessary updates and security measures to mitigate risks associated with this vulnerability.
Affected Version(s)
HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server Version. 1.09.0.0
HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server Version 1.07.0.0
HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server Version 1.10.0.0