CVE-2021-29218

Severity CVSS v4.0:
Pending analysis
Type:
CWE-428 Unquoted Search Path or Element
Publication date:
04/02/2022
Last modified:
09/02/2022

Description

A local unquoted search path security vulnerability has been identified in HPE Agentless Management Service for Windows version(s): Prior to 1.44.0.0, 10.96.0.0. This vulnerability could be exploited locally by a user with high privileges to execute malware that may lead to a loss of confidentiality, integrity, and availability. HPE has provided software updates to resolve the vulnerability in HPE Agentless Management Service for Windows.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hpe:agentless_management:*:*:*:*:*:*:*:* 1.44.0.0 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:x64:*
cpe:2.3:a:hpe:proliant_agentless_management:*:*:*:*:*:*:*:* 10.96.0.0 (excluding)
cpe:2.3:h:hpe:apollo_20:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:apollo_2000_gen_10_plus:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:apollo_6500:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:apollo_6500_gen10_plus:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:apollo_80:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:proliant_dl:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:proliant_ml:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:synergy_480_gen9:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:synergy_620_gen9:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:synergy_660_gen9:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:synergy_680_gen9:-:*:*:*:*:*:*:*