Arbitrary Command Execution Vulnerability in HPE System Management Homepage
CVE-2017-12551

5.6MEDIUM

Key Information:

Vendor
HP
Vendor
CVE Published:
15 February 2018

Summary

A vulnerability has been identified in the HPE System Management Homepage that allows local arbitrary command execution. This affects versions prior to 7.6.1, potentially allowing an attacker with local access to execute unauthorized commands, thereby compromising system integrity and security. It is crucial for organizations using affected versions to apply the necessary updates to mitigate the risks associated with this vulnerability.

References

CVSS V3.1

Score:
5.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.