Remote Unauthenticated Access in HPE Network Automation Products
CVE-2017-5813

6.3MEDIUM

Key Information:

Vendor
HP
Vendor
CVE Published:
4 May 2017

Summary

HPE Network Automation versions ranging from 9.1x to 10.2x exhibit a critical vulnerability that allows remote unauthenticated attackers to gain access to the system. This flaw can potentially enable malicious actors to exploit network management functions without needing valid credentials, leading to unauthorized control and data manipulation. Immediate measures should be taken to patch affected installations to mitigate associated risks.

Affected Version(s)

Network Automation 9.1x, 9.2x, 10.0x, 10.1x and 10.2x

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.