peter bassill · operator
$ cve CVE-2021-29203 JSON

CVE-2021-29203

9.8
CRITICAL · CVSS 3.1 · EPSS 68.3% (pctl 99)

Patch early

EPSS 68.3% — above the 10% action threshold.

Description

A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software, prior to version 1.22. The vulnerability could be remotely exploited to bypass remote authentication leading to execution of arbitrary commands, gaining privileged access, causing denial of service, and changing the configuration. HPE has released a software update to resolve the vulnerability in the HPE Edgeline Infrastructure Manager.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS68.29% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-306
On CISA KEVno
Public exploitnone known
Published2021-05-06
Last modified2026-06-17

Affected (1)

VendorProduct
hpedgeline infrastructure manager

References

→ the Explorer  ·  watch your stack  ·  NVD