CVE-2021-25135: Buffer Overflow
The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local buffer overlfow in spxrestservice setsmtpfunc function.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-25135?
CVE-2021-25135 is a vulnerability in the Baseboard Management Controller (BMC) firmware of certain HPE Cloudline servers.
Which HPE Cloudline servers are affected by CVE-2021-25135?
CVE-2021-25135 affects HPE Cloudline CL5800 Gen9 Server, HPE Cloudline CL5200 Gen9 Server, HPE Cloudline CL4100 Gen10 Server, HPE Cloudline CL3100 Gen10 Server, and HPE Cloudline CL5800 Gen10 Server.
What is the severity of CVE-2021-25135?
CVE-2021-25135 has a severity rating of 7.8 (high).
How does CVE-2021-25135 impact HPE Cloudline servers?
CVE-2021-25135 allows for a local buffer overflow in the spx_restservice setsmtp_func function of the BMC firmware, potentially leading to unauthorized access or denial of service.
How can I fix CVE-2021-25135?
To fix CVE-2021-25135, it is recommended to update the BMC firmware to a non-vulnerable version provided by HPE. Refer to the HPE support page for more information.