CVE-2021-29212
critical · 9.8A remote unauthenticated directory traversal security vulnerability has been identified in HPE iLO Amplifier Pack versions 1.80, 1.81, 1.90 and 1.95. The vulnerability could be remotely exploited to allow an unauthenticated user to run arbitrary code leading complete impact to confidentiality, integrity, and availability of the iLO Amplifier Pack appliance.
9.8
CVSS
13.9%
EPSS (exploit prob.)
96th
EPSS percentile
2021-11-01
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-22
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| hp | ilo_amplifier_pack | 1.80 |
| hp | ilo_amplifier_pack | 1.81 |
| hp | ilo_amplifier_pack | 1.90 |
| hp | ilo_amplifier_pack | 1.95 |
Check a specific version with /api/v1/cve/match.
References
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn04189en_us
- https://www.zerodayinitiative.com/advisories/ZDI-21-1278/
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn04189en_us
- https://www.zerodayinitiative.com/advisories/ZDI-21-1278/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2021-29212