6.7

CVE-2021-29218

A local unquoted search path security vulnerability has been identified in HPE Agentless Management Service for Windows version(s): Prior to 1.44.0.0, 10.96.0.0. This vulnerability could be exploited locally by a user with high privileges to execute malware that may lead to a loss of confidentiality, integrity, and availability. HPE has provided software updates to resolve the vulnerability in HPE Agentless Management Service for Windows.

Data is provided by the National Vulnerability Database (NVD)
HpeAgentless Management Version < 1.44.0.0
   MicrosoftWindows Version- HwPlatformx64
HpeProliant Agentless Management Version < 10.96.0.0
   HpeApollo 20 Version-
   HpeApollo 2000 Gen 10 Plus Version-
   HpeApollo 6500 Version-
   HpeApollo 6500 Gen10 Plus Version-
   HpeApollo 80 Version-
   HpeProliant Dl Version-
   HpeProliant Ml Version-
   HpeSynergy 480 Gen9 Version-
   HpeSynergy 620 Gen9 Version-
   HpeSynergy 660 Gen9 Version-
   HpeSynergy 680 Gen9 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.07% 0.171
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
CWE-428 Unquoted Search Path or Element

The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.