cve/2021/CVE-2021-26576.md
2024-06-18 02:51:15 +02:00

18 lines
837 B
Markdown

### [CVE-2021-26576](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-26576)
![](https://img.shields.io/static/v1?label=Product&message=HPE%20Apollo%2070%20System&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=HPE%20Apollo%2070%20system%20bmc%20firmware%20libifc.so%20uploadsshkey%20function%20has%20a%20command%20injection%20vulnerability.&color=brighgreen)
### Description
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a command injection vulnerability in libifc.so uploadsshkey function.
### POC
#### Reference
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf04080en_us
#### Github
No PoCs found on GitHub currently.