Local Arbitrary Command Execution Vulnerability in HPE System Management Homepage
CVE-2017-12552

5.6MEDIUM

Key Information:

Vendor
HP
Vendor
CVE Published:
15 February 2018

Summary

A vulnerability exists in the HPE System Management Homepage for both Windows and Linux platforms prior to version 7.6.1. This flaw allows local attackers to execute arbitrary commands, which could potentially lead to unauthorized system access or functionality manipulation. It is crucial for administrators to upgrade to the latest version to mitigate this risk. Users are advised to monitor their systems for any unusual activity that may indicate exploitation of this vulnerability.

Affected Version(s)

System Management Homepage for Windows and Linux prior to 7.6.1

References

CVSS V3.1

Score:
5.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.