6.7

CVE-2021-29202

A local buffer overflow vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity 325; HPE SimpliVity 380 Gen10 H version(s): Prior to version 2.78.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HpIntegrated Lights-out 4 Version < 2.78
   HpSimplivity 380 Gen9 Version-
HpIntegrated Lights-out 5 Version < 2.44
   HpProliant Bl460c Gen10 Server Blade Version-
   HpProliant Dl120 Gen10 Server Version-
   HpProliant Dl160 Gen10 Server Version-
   HpProliant Dl180 Gen10 Server Version-
   HpProliant Dl20 Gen10 Server Version-
   HpProliant Dl325 Gen10 Plus Server Version-
   HpProliant Dl325 Gen10 Server Version-
   HpProliant Dl360 Gen10 Server Version-
   HpProliant Dl380 Gen10 Server Version-
   HpProliant Dl385 Gen10 Plus Server Version-
   HpProliant Dl385 Gen10 Server Version-
   HpProliant Dl560 Gen10 Server Version-
   HpProliant Dl580 Gen10 Server Version-
   HpProliant Ml110 Gen10 Server Version-
   HpProliant Ml30 Gen10 Server Version-
   HpProliant Ml350 Gen10 Server Version-
   HpProliant Xl170r Gen10 Server Version-
   HpProliant Xl190r Gen10 Server Version-
   HpProliant Xl230k Gen10 Server Version-
   HpProliant Xl270d Gen10 Server Version-
   HpProliant Xl450 Gen10 Server Version-
   HpSimplivity 2600 Version-
   HpSimplivity 325 Version-
   HpSimplivity 380 Gen10 Version-
   HpSimplivity 380 Gen10 G Version-
   HpSimplivity 380 Gen10 H Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.07% 0.182
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.