### [CVE-2021-26576](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-26576) ![](https://img.shields.io/static/v1?label=Product&message=HPE%20Apollo%2070%20System&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=HPE%20Apollo%2070%20system%20bmc%20firmware%20libifc.so%20uploadsshkey%20function%20has%20a%20command%20injection%20vulnerability.&color=brighgreen) ### Description The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a command injection vulnerability in libifc.so uploadsshkey function. ### POC #### Reference - https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf04080en_us #### Github No PoCs found on GitHub currently.