CVE-2021-29212
A remote unauthenticated directory traversal security vulnerability has been identified in HPE iLO Amplifier Pack versions 1.80, 1.81, 1.90 and 1.95.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 13.9%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
A remote unauthenticated directory traversal security vulnerability has been identified in HPE iLO Amplifier Pack versions 1.80, 1.81, 1.90 and 1.95. The vulnerability could be remotely exploited to allow an unauthenticated user to run arbitrary code leading complete impact to confidentiality, integrity, and availability of the iLO Amplifier Pack appliance.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 13.90% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- hp/ilo amplifier pack
- Source
- security-alert@hpe.com
References
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn04189en_usVendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-21-1278/Third Party Advisory, VDB Entry
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn04189en_usVendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-21-1278/Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.