First published: Fri Feb 04 2022(Updated: )
A local unquoted search path security vulnerability has been identified in HPE Agentless Management Service for Windows version(s): Prior to 1.44.0.0, 10.96.0.0. This vulnerability could be exploited locally by a user with high privileges to execute malware that may lead to a loss of confidentiality, integrity, and availability. HPE has provided software updates to resolve the vulnerability in HPE Agentless Management Service for Windows.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
HPE Agentless Management | <1.44.0.0 | |
Microsoft Windows | ||
Hpe Proliant Agentless Management | <10.96.0.0 | |
Hpe Apollo 20 | ||
Hpe Apollo 2000 Gen 10 Plus | ||
Hpe Apollo 6500 | ||
Hpe Apollo 6500 Gen10 Plus | ||
Hpe Apollo 80 | ||
Hpe Proliant Dl | ||
Hpe Proliant Ml | ||
Hpe Synergy 480 Gen9 | ||
Hpe Synergy 620 Gen9 | ||
Hpe Synergy 660 Gen9 | ||
Hpe Synergy 680 Gen9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-29218 is a local unquoted search path security vulnerability identified in HPE Agentless Management Service for Windows.
Versions prior to 1.44.0.0 of HPE Agentless Management are affected by CVE-2021-29218.
CVE-2021-29218 can be exploited locally by a user with high privileges to execute malware.
CVE-2021-29218 has a severity rating of medium.
To fix CVE-2021-29218, update HPE Agentless Management Service for Windows to version 1.44.0.0 or later.