CVE-2021-25137: Buffer Overflow
The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local buffer overlfow in spxrestservice startflashfunc function.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-25137?
CVE-2021-25137 is a vulnerability in the Baseboard Management Controller (BMC) firmware of certain HPE Cloudline servers.
Which servers are affected by CVE-2021-25137?
CVE-2021-25137 affects the HPE Cloudline CL5800 Gen9, HPE Cloudline CL5200 Gen9, HPE Cloudline CL4100 Gen10, and HPE Cloudline CL3100 Gen10 servers.
What is the severity of CVE-2021-25137?
The severity of CVE-2021-25137 is high, with a CVSS score of 7.8.
How does CVE-2021-25137 impact the affected servers?
CVE-2021-25137 allows for a local buffer overflow in the spx_restservice startflash_func function of the BMC firmware, which can potentially be exploited by an attacker.
How can I fix CVE-2021-25137?
To fix CVE-2021-25137, users should update the BMC firmware of the affected HPE Cloudline servers to a patched version provided by HPE.