Code Injection Vulnerability in HPE StoreServ Management Console
CVE-2021-29214
7.2HIGH
Key Information:
- Vendor
HP
- Vendor
- CVE Published:
- 10 December 2021
What is CVE-2021-29214?
A security flaw has been discovered in the HPE StoreServ Management Console (SSMC) that allows an authenticated administrator to inject malicious code. This vulnerability enables the administrator to escalate their privileges within the SSMC environment. It is crucial to note that only the SSMC is impacted; the managed storage arrays remain unaffected. The vulnerable versions range from 3.4 GA to 3.8.1, and remediation actions should be taken to mitigate potential exploitation.
Affected Version(s)
HPE StoreServ Management Console (SSMC); HPE 3PAR StoreServ Management and Core Software Media 3.4 GA to 3.8.1