Local Buffer Overflow Vulnerability in HPE Cloudline BMC Firmware
CVE-2021-25135
Key Information:
- Vendor
HP
- Vendor
- CVE Published:
- 29 January 2021
What is CVE-2021-25135?
A local buffer overflow vulnerability exists within the Baseboard Management Controller (BMC) in specific HPE Cloudline servers, including the CL5800 Gen9 and Gen10, CL5200 Gen9, and CL4100 Gen10. This flaw in the spx_restservice setsmtp_func function could allow an authenticated attacker to execute arbitrary code, potentially compromising the server’s integrity and leading to unauthorized access or service disruptions.
Affected Version(s)
HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server Version. 1.09.0.0
HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server Version 1.07.0.0
HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server Version 1.10.0.0