CVE-2021-29203 is a critical authentication bypass vulnerability affecting HPE Edgeline Infrastructure Manager versions prior to 1.22. This flaw allows an unauthenticated remote attacker to execute arbitrary commands, gain privileged access, cause denial of service, and alter system configurations. With a CVSS score of 9.8 (CRITICAL) and an EPSS score indicating high exploitability, the vulnerability is easily exploitable over the network with low attack complexity. While not currently listed in CISA KEV, a Nuclei template exists for detection, and HPE has released a patch to address the issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.22CPE matchmatch criteria | cpe:2.3:a:hp:edgeline_infrastructure_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HPE Edgeline Infrastructure Manager v1.21 Authentication Bypass
Apr 30, 2021HPE Edgeline Infrastructure Manager v1.21 Authentication Bypass
Apr 30, 2021HPE Edgeline Infrastructure Manager v1.21 Authentication Bypass
Apr 30, 2021HPE Edgeline Infrastructure Manager v1.21 Authentication Bypass
Apr 30, 2021HPE Edgeline Infrastructure Manager v1.21 Authentication Bypass
Apr 30, 2021