PT-2022-9915 · Hewlett Packard · Hpe Agentless Management Service For Windows
Published
2022-02-04
·
Updated
2022-02-09
·
CVE-2021-29218
CVSS v3.1
6.7
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
HPE Agentless Management Service for Windows versions prior to 1.44.0.0
HPE Agentless Management Service for Windows version 10.96.0.0
Description
A local unquoted search path security issue has been identified. This could be exploited locally by a user with high privileges to execute malware, potentially leading to a loss of confidentiality, integrity, and availability.
Recommendations
For HPE Agentless Management Service for Windows versions prior to 1.44.0.0, update to version 1.44.0.0 or later to resolve the vulnerability.
For HPE Agentless Management Service for Windows version 10.96.0.0, update to a version that includes the fix for this issue, as provided by HPE.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hpe Agentless Management Service For Windows