CVE-2021-29209
MEDIUMHPE Integrated Lights-Out 4 < 2.78 and iLO 5 < 2.44 - Remote DOM-Based Cross-Site Scripting and CRLF Injection
Title source: llmDescription
A remote dom xss, crlf injection vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity 325; HPE SimpliVity 380 Gen10 H version(s): Prior to version 2.78.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_misc
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf04134en_us
Scores
CVSS v3
4.8
EPSS
0.0021
EPSS Percentile
42.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-74
CWE-79
Status
published
Products (2)
hp/integrated_lights-out_4
< 2.78
hp/integrated_lights-out_5
< 2.44
Published
May 25, 2021
Tracked Since
Feb 18, 2026