Lucene search

K
cve[email protected]CVE-2023-4499
HistoryOct 13, 2023 - 5:15 p.m.

CVE-2023-4499

2023-10-1317:15:09
CWE-295
web.nvd.nist.gov
30
hp
thinupdate
utility
security
vulnerability
information disclosure
hp recovery image
software download tool
nvd

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.3 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

37.3%

A potential security vulnerability has been identified in the HP ThinUpdate utility (also known as HP Recovery Image and Software Download Tool) which may lead to information disclosure. HP is releasing mitigation for the potential vulnerability.

Affected configurations

NVD
Node
hpelite_mt645Match-
OR
hpmt21Match-
OR
hpmt22Match-
OR
hpmt31Match-
OR
hpmt32Match-
OR
hpmt43Match-
OR
hpmt44Match-
OR
hpmt45Match-
OR
hpmt46Match-
OR
hppro_mt440_g3Match-
OR
hpt430Match-
OR
hpt530Match-
OR
hpt540Match-
OR
hpt628Match-
OR
hpt630Match-
OR
hpt638Match-
OR
hpt640Match-
OR
hpt730Match-
OR
hpt740Match-
AND
hpthinupdateRange<2.7.15
CPENameOperatorVersion
hp:thinupdatehp thinupdatelt2.7.15

CNA Affected

[
  {
    "vendor": "HP Inc.",
    "product": "HP ThinUpdate",
    "defaultStatus": "affected",
    "versions": [
      {
        "version": "See HP Security Bulletin reference for affected versions.",
        "status": "affected"
      }
    ]
  }
]

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.3 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

37.3%

Related for CVE-2023-4499