Local Arbitrary Command Execution Vulnerability in HPE System Management Homepage
CVE-2017-12552
5.6MEDIUM
Key Information:
- Vendor
- HP
- Vendor
- CVE Published:
- 15 February 2018
Summary
A vulnerability exists in the HPE System Management Homepage for both Windows and Linux platforms prior to version 7.6.1. This flaw allows local attackers to execute arbitrary commands, which could potentially lead to unauthorized system access or functionality manipulation. It is crucial for administrators to upgrade to the latest version to mitigate this risk. Users are advised to monitor their systems for any unusual activity that may indicate exploitation of this vulnerability.
Affected Version(s)
System Management Homepage for Windows and Linux prior to 7.6.1
References
CVSS V3.1
Score:
5.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved