Record summary

CVE-2021-29203 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software, prior to version 1.22. The vulnerability could be remotely exploited to bypass remote authentication leading to execution of arbitrary commands, gaining privileged access, causing denial of service, and changing the configuration. HPE has released a software update to resolve the vulnerability in the HPE Edgeline Infrastructure Manager.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Dec 24, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus

edgeline_infrastructure_manager

Browse HP / edgeline_infrastructure_manager
VulnCheckVersion data not supplied

HPE Edgeline Infrastructure Management Software

CVE ListPrior to version 1.22affected

Nuclei templates

1
ProjectDiscoveryCRITICALHPE Edgeline Infrastructure Manager <1.22 - Authentication BypassCVSS 9.8

HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software, prior to version 1.22 contains an authentication bypass vulnerability which could be remotely exploited to bypass remote authentication and possibly lead to execution of arbitrary commands, gaining privileged access, causing denial of service, and changing the configuration.

Impact

Successful exploitation of this vulnerability could result in unauthorized access to sensitive information, unauthorized configuration changes, or disruption of the affected system.

Remediation

Upgrade to HPE Edgeline Infrastructure Manager version 1.22 or later to mitigate this vulnerability.

WeaknessesCWE-306
Authorsmadrobot
Template tagscve2021cvehpebypasstenablehpvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:hp:edgeline_infrastructure_manager:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3