Lucene search

K
cveHpeCVE-2021-29212
HistoryNov 01, 2021 - 2:15 p.m.

CVE-2021-29212

2021-11-0114:15:07
CWE-22
hpe
web.nvd.nist.gov
28
2
hpe
ilo amplifier pack
remote exploit
directory traversal
vulnerability
nvd
security advisory
cve-2021-29212

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.006

Percentile

77.8%

A remote unauthenticated directory traversal security vulnerability has been identified in HPE iLO Amplifier Pack versions 1.80, 1.81, 1.90 and 1.95. The vulnerability could be remotely exploited to allow an unauthenticated user to run arbitrary code leading complete impact to confidentiality, integrity, and availability of the iLO Amplifier Pack appliance.

Affected configurations

Nvd
Node
hpilo_amplifier_packMatch1.80
OR
hpilo_amplifier_packMatch1.81
OR
hpilo_amplifier_packMatch1.90
OR
hpilo_amplifier_packMatch1.95
VendorProductVersionCPE
hpilo_amplifier_pack1.80cpe:2.3:a:hp:ilo_amplifier_pack:1.80:*:*:*:*:*:*:*
hpilo_amplifier_pack1.81cpe:2.3:a:hp:ilo_amplifier_pack:1.81:*:*:*:*:*:*:*
hpilo_amplifier_pack1.90cpe:2.3:a:hp:ilo_amplifier_pack:1.90:*:*:*:*:*:*:*
hpilo_amplifier_pack1.95cpe:2.3:a:hp:ilo_amplifier_pack:1.95:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "iLO Amplifier Pack",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Ver 1.80, Ver 1.81, Ver 1.90, and Ver 1.95"
      }
    ]
  }
]

Social References

More

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.006

Percentile

77.8%

Related for CVE-2021-29212