Vulnerabilities > CVE-2019-11988 - Unspecified vulnerability in HPE Smart Update Manager

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
hpe
critical
nessus

Summary

A Remote Unauthorized Access vulnerability was identified in HPE Smart Update Manager (SUM) earlier than version 8.3.5.

Nessus

  • NASL familyCGI abuses
    NASL idHP_SUM_USESSHKEY_AUTH_BYPASS.NASL
    descriptionThe HPE Smart Update manager running on the remote host is affected by an authentication bypass vulnerability. An unauthenticated, remote attacker can exploit this, via a specially crafted request, to bypass authentication and execute arbitrary actions defined by the application.
    last seen2020-03-18
    modified2020-02-24
    plugin id133955
    published2020-02-24
    reporterThis script is Copyright (C) 2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/133955
    titleHP Smart Update Manager Remote Unauthorized Access.
  • NASL familyCGI abuses
    NASL idHP_SUM_CVE-2019-11988.NASL
    descriptionThe HPE Smart Update manager running on the remote host is affected by an authentication bypass vulnerability. An unauthenticated, remote attacker can exploit this, via a specially crafted request, to bypass authentication and execute arbitrary actions defined by the application.
    last seen2020-03-18
    modified2019-09-13
    plugin id128768
    published2019-09-13
    reporterThis script is Copyright (C) 2019-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/128768
    titleHP Smart Update Manager Remote Unauthorized Access.