First published: Mon Feb 08 2021(Updated: )
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webupdatecomponent function.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hpe Baseboard Management Controller | <3.0.14.0 | |
HPE Apollo 70 System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25168 is a vulnerability in the Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 that allows for a local buffer overflow.
The severity of CVE-2021-25168 is high with a CVSS score of 7.8.
CVE-2021-25168 affects HPE Baseboard Management Controller versions prior to 3.0.14.0, causing a local buffer overflow in the libifc.so webupdatecomponent function.
No, HPE Apollo 70 System is not affected by CVE-2021-25168.
To fix CVE-2021-25168, update the Baseboard Management Controller (BMC) firmware of HPE Apollo 70 System to version 3.0.14.0 or later.