Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-29219


A potential local buffer overflow vulnerability has been identified in HPE FlexNetwork 5130 EL Switch Series version: Prior to 5130_EI_7.10.R3507P02. HPE has made the following software update to resolve the vulnerability in HPE FlexNetwork 5130 EL Switch Series version 5130_EL_7.10.R3507P02.


Published

2022-02-04T23:15:11.447

Last Modified

2024-11-21T06:00:51.000

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.9

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-120

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System hpe flexnetwork_5130_jg932a_firmware < 5130_ei_7.10.r3507p02 Yes
Hardware hpe flexnetwork_5130_jg932a - No
Operating System hpe flexnetwork_5130_jg933a_firmware < 5130_ei_7.10.r3507p02 Yes
Hardware hpe flexnetwork_5130_jg933a - No
Operating System hpe flexnetwork_5130_jg934a_firmware < 5130_ei_7.10.r3507p02 Yes
Hardware hpe flexnetwork_5130_jg934a - No
Operating System hpe flexnetwork_5130_jg936a_firmware < 5130_ei_7.10.r3507p02 Yes
Hardware hpe flexnetwork_5130_jg936a - No
Operating System hpe flexnetwork_5130_jg937a_firmware < 5130_ei_7.10.r3507p02 Yes
Hardware hpe flexnetwork_5130_jg937a - No
Operating System hpe flexnetwork_5130_jg940a_firmware < 5130_ei_7.10.r3507p02 Yes
Hardware hpe flexnetwork_5130_jg940a - No
Operating System hpe flexnetwork_5130_jg941a_firmware < 5130_ei_7.10.r3507p02 Yes
Hardware hpe flexnetwork_5130_jg941a - No

References