First published: Mon Nov 01 2021(Updated: )
A remote unauthenticated directory traversal security vulnerability has been identified in HPE iLO Amplifier Pack versions 1.80, 1.81, 1.90 and 1.95. The vulnerability could be remotely exploited to allow an unauthenticated user to run arbitrary code leading complete impact to confidentiality, integrity, and availability of the iLO Amplifier Pack appliance.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hp Ilo Amplifier Pack | =1.80 | |
Hp Ilo Amplifier Pack | =1.81 | |
Hp Ilo Amplifier Pack | =1.90 | |
Hp Ilo Amplifier Pack | =1.95 | |
Hewlett Packard Enterprise iLO Amplifier Pack |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-29212 is classified as a critical severity vulnerability due to its potential for remote code execution.
To mitigate CVE-2021-29212, users should upgrade HPE iLO Amplifier Pack to a version that is not affected, specifically versions 1.96 or later.
CVE-2021-29212 affects HPE iLO Amplifier Pack versions 1.80, 1.81, 1.90, and 1.95.
CVE-2021-29212 can be exploited through remote unauthenticated access, allowing attackers to execute arbitrary code.
CVE-2021-29212 can be exploited by unauthenticated users, which significantly increases the risk of attack.