CVE-2021-29218

A local unquoted search path security vulnerability has been identified in HPE Agentless Management Service for Windows version(s): Prior to 1.44.0.0, 10.96.0.0. This vulnerability could be exploited locally by a user with high privileges to execute malware that may lead to a loss of confidentiality, integrity, and availability. HPE has provided software updates to resolve the vulnerability in HPE Agentless Management Service for Windows.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:hpe:agentless_management:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:x64:*

Configuration 2 (hide)

AND
cpe:2.3:a:hpe:proliant_agentless_management:*:*:*:*:*:*:*:*
OR cpe:2.3:h:hpe:apollo_20:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:apollo_2000_gen_10_plus:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:apollo_6500:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:apollo_6500_gen10_plus:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:apollo_80:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:proliant_dl:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:proliant_ml:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:synergy_480_gen9:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:synergy_620_gen9:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:synergy_660_gen9:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:synergy_680_gen9:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-02-04 23:15

Updated : 2024-02-28 18:48


NVD link : CVE-2021-29218

Mitre link : CVE-2021-29218

CVE.ORG link : CVE-2021-29218


JSON object : View

Products Affected

hpe

  • synergy_620_gen9
  • synergy_680_gen9
  • synergy_660_gen9
  • apollo_80
  • proliant_agentless_management
  • apollo_20
  • apollo_2000_gen_10_plus
  • apollo_6500_gen10_plus
  • proliant_ml
  • apollo_6500
  • synergy_480_gen9
  • agentless_management
  • proliant_dl

microsoft

  • windows
CWE
CWE-428

Unquoted Search Path or Element