CVE-2021-25129: Path Traversal
The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local spxrestservice getvideodatafunc function path traversal vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-25129?
CVE-2021-25129 is a baseboard management controller vulnerability in HPE Cloudline servers.
Which HPE Cloudline servers are affected by CVE-2021-25129?
HPE Cloudline CL5800 Gen9 Server, HPE Cloudline CL5200 Gen9 Server, HPE Cloudline CL4100 Gen10 Server, HPE Cloudline CL3100 Gen10 Server, and HPE Cloudline CL5800 Gen10 Server are affected by CVE-2021-25129.
What is the severity of CVE-2021-25129?
CVE-2021-25129 has a severity rating of 7.8 (High).
How does CVE-2021-25129 affect HPE Cloudline servers?
CVE-2021-25129 allows a local attacker to perform a path traversal attack on the baseboard management controller firmware of HPE Cloudline servers.
How can I fix CVE-2021-25129?
To fix CVE-2021-25129, install the appropriate BMC firmware updates provided by HPE and follow any additional mitigation steps mentioned in the advisory.