First published: Tue May 25 2021(Updated: )
A remote xss vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity 325; HPE SimpliVity 380 Gen10 H version(s): Prior to version 2.78.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
HP Integrated Lights-Out 4 | <2.78 | |
Hp Simplivity 380 Gen9 | ||
Hp Integrated Lights-out 5 | <2.44 | |
Hp Proliant Bl460c Gen10 Server Blade | ||
Hp Proliant Dl120 Gen10 Server | ||
Hp Proliant Dl160 Gen10 Server | ||
Hp Proliant Dl180 Gen10 Server | ||
Hp Proliant Dl20 Gen10 Server | ||
Hp Proliant Dl325 Gen10 Plus Server | ||
Hp Proliant Dl325 Gen10 Server | ||
Hp Proliant Dl360 Gen10 Server | ||
Hp Proliant Dl380 Gen10 Server | ||
Hp Proliant Dl385 Gen10 Plus Server | ||
Hp Proliant Dl385 Gen10 Server | ||
Hp Proliant Dl560 Gen10 Server | ||
Hp Proliant Dl580 Gen10 Server | ||
Hp Proliant Ml110 Gen10 Server | ||
Hp Proliant Ml30 Gen10 Server | ||
Hp Proliant Ml350 Gen10 Server | ||
Hp Proliant Xl170r Gen10 Server | ||
Hp Proliant Xl190r Gen10 Server | ||
Hp Proliant Xl230k Gen10 Server | ||
Hp Proliant Xl270d Gen10 Server | ||
Hp Proliant Xl450 Gen10 Server | ||
Hp Simplivity 2600 | ||
Hp Simplivity 325 | ||
Hp Simplivity 380 Gen10 | ||
Hp Simplivity 380 Gen10 G | ||
Hp Simplivity 380 Gen10 H |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-29211 is a remote XSS vulnerability that was discovered in HPE Integrated Lights-Out 4 (iLO 4) and other HPE products.
CVE-2021-29211 has a severity rating of 4.8, which is considered medium.
HPE Integrated Lights-Out 4 (iLO 4), HPE SimpliVity 380 Gen9, HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers, HPE SimpliVity 380 Gen10, HPE SimpliVity 2600, HPE SimpliVity 380 Gen10 G, and HPE SimpliVity 325 are affected by CVE-2021-29211.
To fix CVE-2021-29211, it is recommended to update to the latest version of the affected HPE products and apply any available patches or security updates.
More information about CVE-2021-29211 can be found at the following reference: [link](https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf04134en_us)