MEDIUM · 6.7

CVE-2021-29213

A potential local bypass of security restrictions vulnerability has been identified in HPE ProLiant DL20 Gen10, HPE ProLiant ML30 Gen10, and HPE ProLiant MicroServer Gen10 Plus server's system ROMs pr...

Vulnerability Description

A potential local bypass of security restrictions vulnerability has been identified in HPE ProLiant DL20 Gen10, HPE ProLiant ML30 Gen10, and HPE ProLiant MicroServer Gen10 Plus server's system ROMs prior to version 2.52. The vulnerability could be locally exploited to cause disclosure of sensitive information, denial of service (DoS), and/or compromise system integrity.

CVSS Score

6.7

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
HpeProliant Microserver Gen10 Plus Firmware< 2.52
HpeProliant Microserver Gen10 Plus-
HpeProliant Ml30 Gen10 Server Firmware< 2.52
HpeProliant Ml30 Gen10 Server-
HpeProliant Dl20 Gen10 Server Firmware< 2.52
HpeProliant Dl20 Gen10 Server-

References

FAQ

What is CVE-2021-29213?

CVE-2021-29213 is a vulnerability with a CVSS score of 6.7 (MEDIUM). A potential local bypass of security restrictions vulnerability has been identified in HPE ProLiant DL20 Gen10, HPE ProLiant ML30 Gen10, and HPE ProLiant MicroServer Gen10 Plus server's system ROMs pr...

How severe is CVE-2021-29213?

CVE-2021-29213 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-29213?

Check the references section above for vendor advisories and patch information. Affected products include: Hpe Proliant Microserver Gen10 Plus Firmware, Hpe Proliant Microserver Gen10 Plus, Hpe Proliant Ml30 Gen10 Server Firmware, Hpe Proliant Ml30 Gen10 Server, Hpe Proliant Dl20 Gen10 Server Firmware.