CVE-2021-25138: Buffer Overflow
The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local buffer overlfow in spxrestservice uploadsshkey function.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-25138?
CVE-2021-25138 is a vulnerability in the Baseboard Management Controller (BMC) firmware in certain HPE Cloudline servers, which allows a local buffer overflow in the spx_restservice uploadsshkey function.
Which HPE Cloudline servers are affected by CVE-2021-25138?
HPE Cloudline CL5800 Gen9 Server, HPE Cloudline CL5200 Gen9 Server, HPE Cloudline CL4100 Gen10 Server, HPE Cloudline CL3100 Gen10 Server, and HPE Cloudline CL5800 Gen10 Server are affected.
What is the severity of CVE-2021-25138?
CVE-2021-25138 has a severity rating of 7.8 (High).
How can I fix CVE-2021-25138?
To fix CVE-2021-25138, you should update the BMC firmware of the affected HPE Cloudline servers to a version that addresses the vulnerability.
Where can I find more information about CVE-2021-25138?
You can find more information about CVE-2021-25138 on the HPE support website.