CVE-2021-29218
Severity CVSS v4.0:
Pending analysis
Type:
CWE-428
Unquoted Search Path or Element
Publication date:
04/02/2022
Last modified:
09/02/2022
Description
A local unquoted search path security vulnerability has been identified in HPE Agentless Management Service for Windows version(s): Prior to 1.44.0.0, 10.96.0.0. This vulnerability could be exploited locally by a user with high privileges to execute malware that may lead to a loss of confidentiality, integrity, and availability. HPE has provided software updates to resolve the vulnerability in HPE Agentless Management Service for Windows.
Impact
Base Score 3.x
6.70
Severity 3.x
MEDIUM
Base Score 2.0
4.60
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:hpe:agentless_management:*:*:*:*:*:*:*:* | 1.44.0.0 (excluding) | |
| cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:x64:* | ||
| cpe:2.3:a:hpe:proliant_agentless_management:*:*:*:*:*:*:*:* | 10.96.0.0 (excluding) | |
| cpe:2.3:h:hpe:apollo_20:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hpe:apollo_2000_gen_10_plus:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hpe:apollo_6500:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hpe:apollo_6500_gen10_plus:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hpe:apollo_80:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hpe:proliant_dl:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hpe:proliant_ml:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hpe:synergy_480_gen9:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hpe:synergy_620_gen9:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hpe:synergy_660_gen9:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hpe:synergy_680_gen9:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



