CVE-2021-25128: Path Traversal
The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local spxrestservice gethelpdatafunc function path traversal vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-25128.
Which servers are affected by this vulnerability?
HPE Cloudline CL5800 Gen9 Server, HPE Cloudline CL5200 Gen9 Server, HPE Cloudline CL4100 Gen10 Server, HPE Cloudline CL3100 Gen10 Server, HPE Cloudline CL5800 Gen10 Server are affected by this vulnerability.
What is the severity of CVE-2021-25128?
The severity of CVE-2021-25128 is high, with a CVSS score of 7.8.
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-22.
How can I fix CVE-2021-25128?
To fix CVE-2021-25128, update the BMC firmware to a version that resolves the vulnerability.