Vulnerability identifier: #VU802
Vulnerability risk: Low
CVSSv4.0: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID:
CWE-ID:
CWE-284
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
HPE iMC PLAT
Hardware solutions /
Routers & switches, VoIP, GSM, etc
Vendor: HPE
Description
The vulnerability allows a remote unauthenticated user to access potentially sensitive information and cause DoS conditions.
The weakness exists due to access control error and lets attackers to view important data and cause the target system deny.
Successful exploitation of the vulnerability may result in information disclosure and denial of service on the vulnerable system.
Mitigation
Update to version 7.2.
Vulnerable software versions
HPE iMC PLAT: 3.3 - 7.1
External links
https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c05289984
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.