6.7
CVE-2021-29202
- EPSS 0.07%
- Veröffentlicht 25.05.2021 14:15:07
- Zuletzt bearbeitet 21.11.2024 06:00:48
- Quelle security-alert@hpe.com
- Teams Watchlist Login
- Unerledigt Login
A local buffer overflow vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity 325; HPE SimpliVity 380 Gen10 H version(s): Prior to version 2.78.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hp ≫ Integrated Lights-out 4 Version < 2.78
Hp ≫ Integrated Lights-out 5 Version < 2.44
Hp ≫ Proliant Bl460c Gen10 Server Blade Version-
Hp ≫ Proliant Dl120 Gen10 Server Version-
Hp ≫ Proliant Dl160 Gen10 Server Version-
Hp ≫ Proliant Dl180 Gen10 Server Version-
Hp ≫ Proliant Dl20 Gen10 Server Version-
Hp ≫ Proliant Dl325 Gen10 Plus Server Version-
Hp ≫ Proliant Dl325 Gen10 Server Version-
Hp ≫ Proliant Dl360 Gen10 Server Version-
Hp ≫ Proliant Dl380 Gen10 Server Version-
Hp ≫ Proliant Dl385 Gen10 Plus Server Version-
Hp ≫ Proliant Dl385 Gen10 Server Version-
Hp ≫ Proliant Dl560 Gen10 Server Version-
Hp ≫ Proliant Dl580 Gen10 Server Version-
Hp ≫ Proliant Ml110 Gen10 Server Version-
Hp ≫ Proliant Ml30 Gen10 Server Version-
Hp ≫ Proliant Ml350 Gen10 Server Version-
Hp ≫ Proliant Xl170r Gen10 Server Version-
Hp ≫ Proliant Xl190r Gen10 Server Version-
Hp ≫ Proliant Xl230k Gen10 Server Version-
Hp ≫ Proliant Xl270d Gen10 Server Version-
Hp ≫ Proliant Xl450 Gen10 Server Version-
Hp ≫ Simplivity 2600 Version-
Hp ≫ Simplivity 325 Version-
Hp ≫ Simplivity 380 Gen10 Version-
Hp ≫ Simplivity 380 Gen10 G Version-
Hp ≫ Simplivity 380 Gen10 H Version-
Hp ≫ Proliant Dl120 Gen10 Server Version-
Hp ≫ Proliant Dl160 Gen10 Server Version-
Hp ≫ Proliant Dl180 Gen10 Server Version-
Hp ≫ Proliant Dl20 Gen10 Server Version-
Hp ≫ Proliant Dl325 Gen10 Plus Server Version-
Hp ≫ Proliant Dl325 Gen10 Server Version-
Hp ≫ Proliant Dl360 Gen10 Server Version-
Hp ≫ Proliant Dl380 Gen10 Server Version-
Hp ≫ Proliant Dl385 Gen10 Plus Server Version-
Hp ≫ Proliant Dl385 Gen10 Server Version-
Hp ≫ Proliant Dl560 Gen10 Server Version-
Hp ≫ Proliant Dl580 Gen10 Server Version-
Hp ≫ Proliant Ml110 Gen10 Server Version-
Hp ≫ Proliant Ml30 Gen10 Server Version-
Hp ≫ Proliant Ml350 Gen10 Server Version-
Hp ≫ Proliant Xl170r Gen10 Server Version-
Hp ≫ Proliant Xl190r Gen10 Server Version-
Hp ≫ Proliant Xl230k Gen10 Server Version-
Hp ≫ Proliant Xl270d Gen10 Server Version-
Hp ≫ Proliant Xl450 Gen10 Server Version-
Hp ≫ Simplivity 2600 Version-
Hp ≫ Simplivity 325 Version-
Hp ≫ Simplivity 380 Gen10 Version-
Hp ≫ Simplivity 380 Gen10 G Version-
Hp ≫ Simplivity 380 Gen10 H Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.07% | 0.182 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.