Lucene search

K
cveHpCVE-2010-1968
HistoryJul 15, 2010 - 12:57 p.m.

CVE-2010-1968

2010-07-1512:57:21
CWE-352
hp
web.nvd.nist.gov
27
cve-2010-1968
csrf
hp insight software installer
windows
vulnerability
nvd
remote attackers

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.1

Confidence

Low

EPSS

0.002

Percentile

56.5%

Cross-site request forgery (CSRF) vulnerability in HP Insight Software Installer for Windows before 6.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors, a different vulnerability than CVE-2010-1971.

Affected configurations

Nvd
Node
hpinsight_software_installerRange6.0
OR
hpinsight_software_installerMatch3.00
OR
hpinsight_software_installerMatch3.10
AND
microsoftwindows
VendorProductVersionCPE
hpinsight_software_installer*cpe:2.3:a:hp:insight_software_installer:*:*:*:*:*:*:*:*
hpinsight_software_installer3.00cpe:2.3:a:hp:insight_software_installer:3.00:*:*:*:*:*:*:*
hpinsight_software_installer3.10cpe:2.3:a:hp:insight_software_installer:3.10:*:*:*:*:*:*:*
microsoftwindows*cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.1

Confidence

Low

EPSS

0.002

Percentile

56.5%

Related for CVE-2010-1968