First published: Tue May 25 2021(Updated: )
A remote dom xss, crlf injection vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity 325; HPE SimpliVity 380 Gen10 H version(s): Prior to version 2.78.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
HP Integrated Lights-Out 4 | <2.78 | |
Hp Simplivity 380 Gen9 | ||
Hp Integrated Lights-out 5 | <2.44 | |
Hp Proliant Bl460c Gen10 Server Blade | ||
Hp Proliant Dl120 Gen10 Server | ||
Hp Proliant Dl160 Gen10 Server | ||
Hp Proliant Dl180 Gen10 Server | ||
Hp Proliant Dl20 Gen10 Server | ||
Hp Proliant Dl325 Gen10 Plus Server | ||
Hp Proliant Dl325 Gen10 Server | ||
Hp Proliant Dl360 Gen10 Server | ||
Hp Proliant Dl380 Gen10 Server | ||
Hp Proliant Dl385 Gen10 Plus Server | ||
Hp Proliant Dl385 Gen10 Server | ||
Hp Proliant Dl560 Gen10 Server | ||
Hp Proliant Dl580 Gen10 Server | ||
Hp Proliant Ml110 Gen10 Server | ||
Hp Proliant Ml30 Gen10 Server | ||
Hp Proliant Ml350 Gen10 Server | ||
Hp Proliant Xl170r Gen10 Server | ||
Hp Proliant Xl190r Gen10 Server | ||
Hp Proliant Xl230k Gen10 Server | ||
Hp Proliant Xl270d Gen10 Server | ||
Hp Proliant Xl450 Gen10 Server | ||
Hp Simplivity 2600 | ||
Hp Simplivity 325 | ||
Hp Simplivity 380 Gen10 | ||
Hp Simplivity 380 Gen10 G | ||
Hp Simplivity 380 Gen10 H |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this HPE vulnerability is CVE-2021-29210.
The severity level of CVE-2021-29210 is medium, with a severity value of 4.8.
CVE-2021-29210 affects HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; and HPE SimpliVity 325.
CVE-2021-29210 is a remote DOM XSS and CRLF Injection vulnerability discovered in HPE Integrated Lights-Out 4 (iLO 4), HPE SimpliVity 380 Gen9, HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers, HPE SimpliVity 380 Gen10, HPE SimpliVity 2600, HPE SimpliVity 380 Gen10 G, and HPE SimpliVity 325.
You can find more information about CVE-2021-29210 at the following reference: [link](https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf04134en_us).