Lucene search

K
kasperskyKaspersky LabKLA10458
HistoryJan 10, 2014 - 12:00 a.m.

KLA10458 Multiple vulnerabilities in HP SMH

2014-01-1000:00:00
Kaspersky Lab
threats.kaspersky.com
107

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.2 Medium

AI Score

Confidence

Low

0.95 High

EPSS

Percentile

99.3%

Multiple vulnerabilities was found in HP SMH. By exploiting these vulnerabilities malicious users can conduct XSS, CSRF and clicjacking attacks via unspecified vectors. These vulnerabilities can be exploited remotely.

Original advisories

HP bulletin

Related products

HP-System-Management-Homepage

CVE list

CVE-2013-6712 critical

CVE-2013-6422 warning

CVE-2014-2641 high

CVE-2014-2640 warning

CVE-2014-2642 warning

CVE-2013-6420 critical

CVE-2013-4545 warning

Solution

Update to latest version

Get HP SMH

Impacts

  • XSS/CSS

Cross site scripting. Exploitation of vulnerabilities with this impact can lead to partial interception of information transmitted between user and site.

Affected Products

  • HP System Management Homepage (SMH) versions earlier than 7.4

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.2 Medium

AI Score

Confidence

Low

0.95 High

EPSS

Percentile

99.3%