First published: Mon Feb 08 2021(Updated: )
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so websetlicensecfg function.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hpe Baseboard Management Controller | <3.0.14.0 | |
HPE Apollo 70 System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-25171 is high (severity value: 7.8).
The HPE Apollo 70 System with Baseboard Management Controller (BMC) firmware versions up to but not including 3.0.14.0 are affected by CVE-2021-25171.
To fix CVE-2021-25171, update the Baseboard Management Controller (BMC) firmware to version 3.0.14.0 or newer.
The Common Weakness Enumeration (CWE) IDs of CVE-2021-25171 are CWE-119 and CWE-120.
You can find more information about CVE-2021-25171 on the HPE support website: [link](https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf04080en_us)