← Vulnerability feed

Vulnerability record · CVE-2021-29203 · published 6 May 2021

CVE-2021-29203: HPE Edgeline Infrastructure Manager authentication bypass allows command execution

Hp · Edgeline Infrastructure Manager

HPE Edgeline Infrastructure Manager before version 1.22 contains a missing-authentication flaw (CWE-306) in a critical function. An unauthenticated remote attacker can bypass remote authentication and then execute arbitrary commands, gain privileged access, cause denial of service, and change configuration. The vendor has released a software update fixing the issue.

9.8 CVSS 3.1 Critical EPSS 68% · top 0.7% CWE-306 · Missing authentication for critical function
9.8CVSS 3.1 base score, v2 10.0
68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software, prior to version 1.22. The vulnerability could be remotely exploited to bypass remote authentication leading to execution of arbitrary commands, gaining privileged access, causing denial of service, and changing the configuration. HPE has released a software update to resolve the vulnerability in the HPE Edgeline Infrastructure Manager.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no authentication or interaction, and a public exploit reference make this a high-urgency patch despite absence from KEV.

What it is

HPE Edgeline Infrastructure Manager before version 1.22 contains a missing-authentication flaw (CWE-306) in a critical function. An unauthenticated remote attacker can bypass remote authentication and then execute arbitrary commands, gain privileged access, cause denial of service, and change configuration. The vendor has released a software update fixing the issue.

Impact

An attacker gains privileged access to the management software and can run arbitrary commands, alter configuration, and disrupt availability. Because the product manages edge infrastructure, compromise can extend to the managed devices.

Attack surface

Reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The flaw sits in a critical function that fails to enforce authentication.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.68293, 99.3rd percentile) and a public exploit reference exists (Tenable TRA-2021-15), indicating meaningful exploitation likelihood. No ransomware association is documented.

What to do

  • Upgrade HPE Edgeline Infrastructure Manager to version 1.22 or later per the HPE advisory.
  • If immediate patching is not possible, restrict network access to the management interface to trusted administrative networks only.
  • Place the management interface behind a VPN or jump host and block exposure to the internet.
  • Audit and rotate credentials and review configuration for unauthorized changes on any instance that was internet-exposed.
  • Monitor HPE advisories for follow-up updates to the fix.

Detection

  • Review web and application logs for requests to critical management endpoints that succeed without an authenticated session.
  • Alert on unexpected process or command execution spawned by the Edgeline Infrastructure Manager service.
  • Monitor for configuration changes and new privileged accounts on the management host.
  • Hunt for scanning or exploit attempts against the management interface from untrusted source IPs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-29203 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-7199Hp edgeline infrastructure manager improper authentication vulnerabilityA security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Softwar…EPSS 9.6%8.8CVE-2026-67277MikroTik RouterOS btest missing authentication leaks kernel memory and crashes kernelRouterOS accepts a "related" btest connection before the primary session is authenticated, letting an unauthenticated client start an IPv4 UDP test. …KEVEPSS 1.6%analysed8.8CVE-2026-59822LiteLLM MCP endpoint auth bypass via OAuth2 passthrough fallbackLiteLLM's MCP Streamable HTTP endpoint, prior to 1.84.0, let an unauthenticated attacker send a fabricated Authorization header that triggered an OAu…KEVEPSS 0.84%analysed9.3CVE-2026-72529TrueConf Server missing authentication allows remote script executionTrueConf Server versions 5.3.X through 5.3.9, 5.4.X through 5.4.9, 5.5.X through 5.5.5, and earlier expose an undocumented function on port 4307/TCP …KEVEPSS 1.5%analysed9.8CVE-2026-46817Oracle E-Business Suite Payments missing authentication allows takeoverOracle Payments in Oracle E-Business Suite 12.2.3 through 12.2.15 contains an easily exploitable flaw in the File Transmission component. An unauthen…KEVEPSS 0.81%analysed9.8CVE-2026-56164Microsoft SharePoint Server missing authentication allows privilege elevationMicrosoft Office SharePoint Server contains a missing authentication flaw in a critical function (CWE-306), letting an unauthenticated attacker reach…KEVEPSS 1.0%analysed9.8CVE-2026-20253Splunk Enterprise PostgreSQL sidecar missing authentication allows file writesSplunk Enterprise 10.2 below 10.2.4 and 10.x below 10.0.7 expose a PostgreSQL sidecar service endpoint that lacks authentication controls. Any networ…KEVEPSS 97%analysed9.8CVE-2026-35273Oracle PeopleSoft PeopleTools missing authentication allows takeoverOracle PeopleSoft Enterprise PeopleTools (Updates Environment Management component) in versions 8.61 and 8.62 is missing authentication for a critica…KEVEPSS 9.4%analysed

Source: NIST National Vulnerability Database (record CVE-2021-29203), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.