GPU VulnDB

Database/Firmware, BMC & network fabric

BMC firmware on the HPE Cloudline whitebox line: An attacker directs the BMC's video-deletion routine at arbitrary

CVE-2021-25124Firmware, BMC & network fabriccurated

Impact

An attacker directs the BMC's video-deletion routine at arbitrary filesystem paths, deleting files inside the controller. Destroying the right files on a BMC means destroying its configuration, its credential store, or its ability to boot - a denial of service against the out-of-band plane on nodes you may not be able to reach any other way. It also destroys the BMC-side record of what happened, which makes it a useful anti-forensics step after a more serious compromise. The broader operator lesson is inventory: Cloudline nodes look like HPE in your asset database but share a BMC codebase with the ODM whiteboxes, and this is one of sixteen CVEs published against that BMC's REST service in a single disclosure. CL5800 Gen9, CL5200 Gen9, CL4100 Gen10, CL3100 Gen10 and CL5800 Gen10. Path traversal in the deletevideo_func handler of spx_restservice. Cloudline is HPE's ODM-manufactured whitebox range and runs a MegaRAC-derived BMC, not iLO, so iLO advisories and iLO tooling do not cover it.

Who can reach it

Access to the BMC's spx_restservice REST interface on the management network. The advisory characterises the path as local to the BMC, meaning it needs a session against the controller rather than pure network anonymity.

What to do

BMC firmware update per HPE's Cloudline advisory - HPE does publish a readable advisory document for this line, which puts it ahead of most whitebox vendors. Flash per node, out of band. The inventory action matters as much as the flash: audit your fleet for Cloudline nodes specifically and confirm they are being tracked against Cloudline BMC advisories rather than iLO ones, because tooling that assumes 'HPE server means iLO' will silently report them as covered when they are not.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.