CVE-2021-29218
A local unquoted search path security vulnerability has been identified in HPE Agentless Management Service for Windows version(s): Prior to 1.44.0.0, 10.96.0.0. This vulnerability could be exploited locally by a user with high privileges to execute malware that may lead to a loss of confidentiality, integrity, and availability. HPE has provided software updates to resolve the vulnerability in HPE Agentless Management Service for Windows.
Published:Feb 4, 2022
Last Modified:Nov 21, 2024
EPS:Feb 4, 2022
EPSS Score:0.00065
CVSS Score:6.7
Affected Products
Vendor
Product
Action
Vendor
Hpe
Product
Agentless Management
Hpe
Agentless Management
Vendor
Hpe
Product
Apollo 20
Hpe
Apollo 20
Vendor
Hpe
Product
Apollo 2000 Gen 10 Plus
Hpe
Apollo 2000 Gen 10 Plus
Vendor
Hpe
Product
Apollo 6500
Hpe
Apollo 6500
Vendor
Hpe
Product
Apollo 6500 Gen10 Plus
Hpe
Apollo 6500 Gen10 Plus
Vendor
Hpe
Product
Apollo 80
Hpe
Apollo 80
Vendor
Hpe
Product
Proliant Agentless Management
Hpe
Proliant Agentless Management
Vendor
Hpe
Product
Proliant Dl
Hpe
Proliant Dl
Vendor
Hpe
Product
Proliant Ml
Hpe
Proliant Ml
Vendor
Hpe
Product
Synergy 480 Gen9
Hpe
Synergy 480 Gen9
Vendor
Hpe
Product
Synergy 620 Gen9
Hpe
Synergy 620 Gen9
Vendor
Hpe
Product
Synergy 660 Gen9
Hpe
Synergy 660 Gen9
Vendor
Hpe
Product
Synergy 680 Gen9
Hpe
Synergy 680 Gen9
Vendor
Microsoft
Product
Windows
Microsoft
Windows
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
