CVE-2021-29203
HP edgeline_infrastructure_manager Missing Authentication for Critical Function
Record summary
CVE-2021-29203 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software, prior to version 1.22. The vulnerability could be remotely exploited to bypass remote authentication leading to execution of arbitrary commands, gaining privileged access, causing denial of service, and changing the configuration. HPE has released a software update to resolve the vulnerability in the HPE Edgeline Infrastructure Manager.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Dec 24, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
edgeline_infrastructure_managerBrowse HP / edgeline_infrastructure_manager | VulnCheck | Version data not supplied | |
HPE Edgeline Infrastructure Management Software | CVE List | Prior to version 1.22 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALHPE Edgeline Infrastructure Manager <1.22 - Authentication BypassCVSS 9.8
HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software, prior to version 1.22 contains an authentication bypass vulnerability which could be remotely exploited to bypass remote authentication and possibly lead to execution of arbitrary commands, gaining privileged access, causing denial of service, and changing the configuration.
Impact
Successful exploitation of this vulnerability could result in unauthorized access to sensitive information, unauthorized configuration changes, or disruption of the affected system.
Remediation
Upgrade to HPE Edgeline Infrastructure Manager version 1.22 or later to mitigate this vulnerability.
Source: ProjectDiscovery