CVE-2021-25124: Path Traversal
The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local spxrestservice deletevideofunc function path traversal vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this security issue?
The vulnerability ID is CVE-2021-25124.
What is the severity of CVE-2021-25124?
The severity of CVE-2021-25124 is high with a severity value of 7.8.
Which software versions are affected by CVE-2021-25124?
Hpe Cloudline Cl3100 Gen10 Server Firmware 1.08.0.0 and 1.10.0.0, Hpe Cloudline Cl4100 Gen10 Server Firmware 1.08.0.0 and 1.10.0.0, Hpe Cloudline Cl5200 Gen9 Server Firmware 1.07.0.0, and Hpe Cloudline Cl5800 Gen10 Server Firmware 1.08.0.0 and 1.09.0.0 are affected by CVE-2021-25124.
How can I fix CVE-2021-25124?
Update the BMC firmware on HPE Cloudline CL5800 Gen9 Server, HPE Cloudline CL5200 Gen9 Server, HPE Cloudline CL4100 Gen10 Server, HPE Cloudline CL3100 Gen10 Server, and HPE Cloudline CL5800 Gen10 Server to the latest version to fix CVE-2021-25124.
Where can I find more information about CVE-2021-25124?
You can find more information about CVE-2021-25124 on the HPE support website.