PT-2021-16440 · Hewlett Packard · Hpe Apollo 70 System

Published

2021-02-08

·

Updated

2021-02-10

·

CVE-2021-25168

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: HPE Apollo 70 System versions prior to 3.0.14.0
Description: The issue is related to a local buffer overflow in the libifc.so webupdatecomponent function within the Baseboard Management Controller (BMC) firmware. This overflow can potentially be exploited.
Recommendations: For versions prior to 3.0.14.0, update the BMC firmware to version 3.0.14.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the webupdatecomponent function in the libifc.so library until the update can be applied.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-25168

Affected Products

Hpe Apollo 70 System