First published: Fri Jan 29 2021(Updated: )
The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local buffer overlfow in spx_restservice generatesslcertificate_func function.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hpe Cloudline Cl3100 Gen10 Server Firmware | =1.08.0.0 | |
Hpe Cloudline Cl3100 Gen10 Server Firmware | =1.10.0.0 | |
HPE Cloudline CL3100 Gen10 Server | ||
Hpe Cloudline Cl4100 Gen10 Server Firmware | =1.08.0.0 | |
Hpe Cloudline Cl4100 Gen10 Server Firmware | =1.10.0.0 | |
HPE Cloudline CL4100 Gen10 Server | ||
Hpe Cloudline Cl5200 Gen9 Server Firmware | =1.07.0.0 | |
HPE Cloudline CL5200 Gen9 Server | ||
Hpe Cloudline Cl5800 Gen10 Server Firmware | =1.08.0.0 | |
HPE Cloudline CL5800 Gen10 Server | ||
Hpe Cloudline Cl5800 Gen9 Server Firmware | =1.09.0.0 | |
HPE Cloudline CL5800 Gen9 Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25127 is a vulnerability in the Baseboard Management Controller (BMC) firmware of HPE Cloudline servers.
CVE-2021-25127 affects HPE Cloudline CL5800 Gen9 Server through its BMC firmware.
CVE-2021-25127 has a severity rating of 7.8 (High).
To fix CVE-2021-25127, update the BMC firmware of the affected HPE Cloudline servers to the latest version.
More information about CVE-2021-25127 can be found at the following link: [CVE-2021-25127](https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf04073en_us).