Files
CVEs-PoC/2021/CVE-2021-25172.md
2025-09-29 21:09:30 +02:00

18 lines
890 B
Markdown

### [CVE-2021-25172](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25172)
![](https://img.shields.io/static/v1?label=Product&message=HPE%20Apollo%2070%20System&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=Prior%20to%20Version%203.0.14.0%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=HPE%20Apollo%2070%20system%20bmc%20firmware%20libifc.so%20websetdefaultlangcfg%20function%20has%20a%20command%20injection%20vulnerability.&color=brightgreen)
### Description
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a command injection vulnerability in libifc.so websetdefaultlangcfg function.
### POC
#### Reference
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf04080en_us
#### Github
No PoCs found on GitHub currently.