First published: Thu Apr 01 2021(Updated: )
A potential security vulnerability has been identified in HPE Superdome Flex server. A denial of service attack can be remotely exploited leaving hung connections to the BMC web interface. The monarch BMC must be rebooted to recover from this situation. Other BMC management is not impacted. HPE has made the following software update to resolve the vulnerability in HPE Superdome Flex Server: Superdome Flex Server Firmware 3.30.142 or later.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hpe Superdome Flex Server Firmware | <3.30.142 | |
HPE Superdome Flex Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-26581 is a potential security vulnerability identified in the HPE Superdome Flex server where a denial of service attack can leave hung connections to the BMC web interface, requiring a reboot of the monarch BMC for recovery.
CVE-2021-26581 can be exploited remotely through a denial of service attack, causing hung connections to the BMC web interface.
The impact of CVE-2021-26581 is a denial of service attack that can leave hung connections to the BMC web interface, requiring a reboot of the monarch BMC for recovery.
The severity of CVE-2021-26581 is medium with a CVSS score of 6.5.
To fix CVE-2021-26581, update the HPE Superdome Flex server firmware to version 3.30.142 or higher as recommended by HPE.