#VU51638 Buffer overflow in Apollo 70 System - CVE-2021-26570
Published: March 23, 2021
Apollo 70 System
Hewlett Packard Enterprise Development LP
Description
The vulnerability allows a local user to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the Baseboard Management Controller (BMC) firmwares in "libifc.so" webifc_setadconfig function. A local user can trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.