HP SoftPaqs Vulnerable to Arbitrary Code Execution
CVE-2024-28893
7.7HIGH
What is CVE-2024-28893?
Certain HP software packages, known as SoftPaqs, exhibit a vulnerability that allows for arbitrary code execution due to modifications in the SoftPaq configuration file after extraction. This could potentially lead to unauthorized actions being performed on the affected systems. HP has acknowledged the issue and provided updated software packages to address the vulnerability, urging users to implement the latest updates for enhanced security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
HP software packages (SoftPaqs) See HP Security Bulletin reference for affected versions.
References
CVSS V3.1
Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved