Local Authentication Bypass in HPE System Management Homepage for Windows and Linux
CVE-2017-12549
5.6MEDIUM
Key Information:
- Vendor
- HP
- Vendor
- CVE Published:
- 15 February 2018
Summary
The HPE System Management Homepage for Windows and Linux contains a local authentication bypass vulnerability affecting versions prior to 7.6.1. This flaw may allow unauthorized access to sensitive system management functions, enabling potential attackers to assume administrative roles without proper credentials.
Affected Version(s)
System Management Homepage for Windows and Linux prior to 7.6.1
References
CVSS V3.1
Score:
5.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved