CVE-2021-29209: XSS
A remote dom xss, crlf injection vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity 325; HPE SimpliVity 380 Gen10 H version(s): Prior to version 2.78.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this HPE Integrated Lights-Out vulnerability?
The vulnerability ID is CVE-2021-29209.
What is the severity of CVE-2021-29209?
The severity of CVE-2021-29209 is medium (4.8).
What software is affected by CVE-2021-29209?
HPE Integrated Lights-Out 4 (iLO 4), HPE SimpliVity 380 Gen9, HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers, HPE SimpliVity 380 Gen10, HPE SimpliVity 2600, HPE SimpliVity 380 Gen10 G, HPE SimpliVity 325, HPE SimpliVity 380 Gen10 H are affected by CVE-2021-29209.
What is the vulnerability type of CVE-2021-29209?
CVE-2021-29209 is a remote DOM XSS and CRLF injection vulnerability.
How can I fix CVE-2021-29209?
To fix CVE-2021-29209, it is recommended to apply the necessary updates provided by HPE. Please refer to the official reference link for more information.