Lucene search

K
cve[email protected]CVE-2023-30905
HistoryJun 16, 2023 - 9:15 p.m.

CVE-2023-30905

2023-06-1621:15:09
web.nvd.nist.gov
21
cve-2023-30905
mc990 x
uv300 rmc
default configuration
inadequate
privilege escalation
nvd

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.5 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

The MC990 X and UV300 RMC component has and inadequate default configuration that could be exploited to obtain enhanced privilege.

Affected configurations

NVD
Node
hpesgi_uv_300_rmc_firmwareRange1.2.7
AND
hpesgi_uv_300_rmcMatch-
Node
hpeintegrity_mc990_x_server_rmc_firmwareRange1.2.7
AND
hpeintegrity_mc990_x_server_rmcMatch-

CNA Affected

[
  {
    "versions": [
      {
        "version": "0",
        "status": "affected",
        "lessThan": "1.2.7",
        "versionType": "semver"
      }
    ],
    "product": "HPE MC990 X RMC firmware",
    "vendor": "Hewlett Packard Enterprise (HPE)"
  }
]

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.5 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

Related for CVE-2023-30905