Access Control Bypass in HPE XP7 Command View by HPE
CVE-2016-4381

4.5MEDIUM

Key Information:

Vendor
HP
Vendor
CVE Published:
8 September 2016

Summary

HPE XP7 Command View Advanced Edition, specifically versions 6.x through 8.x before 8.4.1-02, has a vulnerability that allows local users to bypass established access restrictions when the Replication Manager and Device Manager features are enabled. This can lead to unauthorized access to sensitive configurations and system controls, potentially compromising data integrity and availability.

References

CVSS V3.1

Score:
4.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.