Local Buffer Overflow in HPE Integrated Lights-Out 4 and 5 Products
CVE-2021-29202
Key Information:
- Vendor
- HP
- Vendor
- CVE Published:
- 25 May 2021
Summary
A local buffer overflow vulnerability has been identified in multiple HPE Integrated Lights-Out products, including iLO 4 and iLO 5 for Gen10 Servers, and various HPE SimpliVity models. This vulnerability affects versions prior to 2.78, potentially allowing unauthorized users to execute arbitrary code by sending crafted input to the affected products.
Affected Version(s)
HPE Integrated Lights-Out 4 (iLO 4) For HPE Gen9 servers; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers Prior to HPE Integrated Lights-Out 4 (iLO 4) version 2.78
HPE Integrated Lights-Out 4 (iLO 4) For HPE Gen9 servers; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers Prior to HPE Integrated Lights-Out 5 (iLO 5) version 2.44
HPE Integrated Lights-Out 4 (iLO 4) For HPE Gen9 servers; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers = unspecified
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved