Local Buffer Overflow in HPE Cloudline Server BMC Firmware
CVE-2021-25138
Key Information:
- Vendor
HP
- Vendor
- CVE Published:
- 29 January 2021
What is CVE-2021-25138?
A local buffer overflow vulnerability exists in the Baseboard Management Controller (BMC) firmware for HPE Cloudline servers. An attacker with local access can exploit the 'uploadsshkey' function of spx_restservice, potentially allowing unauthorized actions on the affected system. It is crucial for users to apply the latest firmware updates to mitigate risks associated with this vulnerability.
Affected Version(s)
HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server Version. 1.09.0.0
HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server Version 1.07.0.0
HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server Version 1.10.0.0