HIGH · 7.8

CVE-2021-25129

The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL58...

Vulnerability Description

The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local spx_restservice getvideodata_func function path traversal vulnerability.

CVSS Score

7.8

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
HpeCloudline Cl3100 Gen10 Server Firmware1.08.0.0
HpeCloudline Cl3100 Gen10 Server-
HpeCloudline Cl4100 Gen10 Server Firmware1.08.0.0
HpeCloudline Cl4100 Gen10 Server-
HpeCloudline Cl5200 Gen9 Server Firmware1.07.0.0
HpeCloudline Cl5200 Gen9 Server-
HpeCloudline Cl5800 Gen10 Server Firmware1.08.0.0
HpeCloudline Cl5800 Gen10 Server-
HpeCloudline Cl5800 Gen9 Server Firmware1.09.0.0
HpeCloudline Cl5800 Gen9 Server-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-25129?

CVE-2021-25129 is a vulnerability with a CVSS score of 7.8 (HIGH). The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL58...

How severe is CVE-2021-25129?

CVE-2021-25129 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-25129?

Check the references section above for vendor advisories and patch information. Affected products include: Hpe Cloudline Cl3100 Gen10 Server Firmware, Hpe Cloudline Cl3100 Gen10 Server, Hpe Cloudline Cl4100 Gen10 Server Firmware, Hpe Cloudline Cl4100 Gen10 Server, Hpe Cloudline Cl5200 Gen9 Server Firmware.