Vulnerability record · CVE-2021-29203 · published 6 May 2021
CVE-2021-29203: HPE Edgeline Infrastructure Manager authentication bypass allows command execution
Hp · Edgeline Infrastructure Manager
HPE Edgeline Infrastructure Manager before version 1.22 contains a missing-authentication flaw (CWE-306) in a critical function. An unauthenticated remote attacker can bypass remote authentication and then execute arbitrary commands, gain privileged access, cause denial of service, and change configuration. The vendor has released a software update fixing the issue.
Description
A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software, prior to version 1.22. The vulnerability could be remotely exploited to bypass remote authentication leading to execution of arbitrary commands, gaining privileged access, causing denial of service, and changing the configuration. HPE has released a software update to resolve the vulnerability in the HPE Edgeline Infrastructure Manager.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication or interaction, and a public exploit reference make this a high-urgency patch despite absence from KEV.
What it is
HPE Edgeline Infrastructure Manager before version 1.22 contains a missing-authentication flaw (CWE-306) in a critical function. An unauthenticated remote attacker can bypass remote authentication and then execute arbitrary commands, gain privileged access, cause denial of service, and change configuration. The vendor has released a software update fixing the issue.
Impact
An attacker gains privileged access to the management software and can run arbitrary commands, alter configuration, and disrupt availability. Because the product manages edge infrastructure, compromise can extend to the managed devices.
Attack surface
Reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The flaw sits in a critical function that fails to enforce authentication.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.68293, 99.3rd percentile) and a public exploit reference exists (Tenable TRA-2021-15), indicating meaningful exploitation likelihood. No ransomware association is documented.
What to do
- Upgrade HPE Edgeline Infrastructure Manager to version 1.22 or later per the HPE advisory.
- If immediate patching is not possible, restrict network access to the management interface to trusted administrative networks only.
- Place the management interface behind a VPN or jump host and block exposure to the internet.
- Audit and rotate credentials and review configuration for unauthorized changes on any instance that was internet-exposed.
- Monitor HPE advisories for follow-up updates to the fix.
Detection
- Review web and application logs for requests to critical management endpoints that succeed without an authenticated session.
- Alert on unexpected process or command execution spawned by the Edgeline Infrastructure Manager service.
- Monitor for configuration changes and new privileged accounts on the management host.
- Hunt for scanning or exploit attempts against the management interface from untrusted source IPs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn04124en_us | Vendor Advisory |
| https://www.tenable.com/security/research/tra-2021-15 | ExploitThird Party Advisory |
| https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn04124en_us | Vendor Advisory |
| https://www.tenable.com/security/research/tra-2021-15 | ExploitThird Party Advisory |
Track CVE-2021-29203 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-29203), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.