MEDIUM · 6.5

CVE-2021-26581

A potential security vulnerability has been identified in HPE Superdome Flex server. A denial of service attack can be remotely exploited leaving hung connections to the BMC web interface. The monarch...

Vulnerability Description

A potential security vulnerability has been identified in HPE Superdome Flex server. A denial of service attack can be remotely exploited leaving hung connections to the BMC web interface. The monarch BMC must be rebooted to recover from this situation. Other BMC management is not impacted. HPE has made the following software update to resolve the vulnerability in HPE Superdome Flex Server: Superdome Flex Server Firmware 3.30.142 or later.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
HpeSuperdome Flex Server Firmware< 3.30.142
HpeSuperdome Flex Server-

References

FAQ

What is CVE-2021-26581?

CVE-2021-26581 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A potential security vulnerability has been identified in HPE Superdome Flex server. A denial of service attack can be remotely exploited leaving hung connections to the BMC web interface. The monarch...

How severe is CVE-2021-26581?

CVE-2021-26581 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-26581?

Check the references section above for vendor advisories and patch information. Affected products include: Hpe Superdome Flex Server Firmware, Hpe Superdome Flex Server.