Local Buffer Overflow in HPE Cloudline Server BMC Firmware
CVE-2021-25137
Key Information:
- Vendor
HP
- Vendor
- CVE Published:
- 29 January 2021
What is CVE-2021-25137?
A local buffer overflow vulnerability exists in the Baseboard Management Controller (BMC) firmware of multiple HPE Cloudline Server models. This issue is found in the spx_restservice startflash_func function and could allow an attacker to potentially execute arbitrary code or disrupt service on affected server systems. Users are advised to update to the latest firmware versions to mitigate associated risks. For detailed mitigation steps, refer to the official documentation.
Affected Version(s)
HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server Version. 1.09.0.0
HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server Version 1.07.0.0
HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server Version 1.10.0.0