First published: Mon Feb 08 2021(Updated: )
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webgetactivexcfg function.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hpe Baseboard Management Controller | <3.0.14.0 | |
HPE Apollo 70 System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-26572.
The title of the vulnerability is 'The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0...'
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webgetactivexcfg function.
The HPE Baseboard Management Controller version up to 3.0.14.0 is affected by this vulnerability.
The severity of CVE-2021-26572 is high with a CVSS score of 7.8.
To fix CVE-2021-26572, update the HPE Baseboard Management Controller firmware to version 3.0.14.0 or later.
No, HPE Apollo 70 System is not vulnerable to CVE-2021-26572.
The Common Weakness Enumeration (CWE) codes for this vulnerability are 119 and 120.
You can find more information about CVE-2021-26572 at the following reference link: [https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf04080en_us](https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf04080en_us)