Local Buffer Overflow in HPE Cloudline Servers' BMC Firmware
CVE-2021-25134
Key Information:
- Vendor
HP
- Vendor
- CVE Published:
- 29 January 2021
What is CVE-2021-25134?
The Baseboard Management Controller (BMC) in several HPE Cloudline server models contains a local buffer overflow vulnerability within the spx_restservice setremoteimageinfo_func function. Attackers with local access could exploit this issue to manipulate the server's firmware, potentially leading to unauthorized actions on the system. Thus, it is crucial for organizations using the affected HPE Cloudline servers to apply firmware updates and take necessary security measures to mitigate this risk.
Affected Version(s)
HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server Version. 1.09.0.0
HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server Version 1.07.0.0
HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server Version 1.10.0.0