CVE-2018-7111
 
Severity Score
5.3
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
A remote unauthorized access vulnerability was identified in HPE UIoT versions 1.5, 1.4.0, 1.4.1, 1.4.2, 1.2.4.2. Specifically, there is a malfunction identified in some section of the DSM portal and some DSM APIs. The impact of the malfunction is that the info can be changed by other users.
Se ha identificado una vulnerabilidad de acceso remoto no autorizado en HPE UIoT en versiones 1.5, 1.4.0, 1.4.1, 1.4.2 y 1.2.4.2. Específicamente, hay un mal funcionamiento identificado en algunas secciones del portal DSM y algunas API DSM. El impacto de este mal funcionamiento es que otros usuarios pueden modificar esta información.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2018-02-15 CVE Reserved
- 2018-10-17 CVE Published
- 2024-08-24 EPSS Updated
- 2024-09-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/105704 | Third Party Advisory | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/151691 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Hp Search vendor "Hp" | Universal Internet Of Things Search vendor "Hp" for product "Universal Internet Of Things" | 1.2.4.2 Search vendor "Hp" for product "Universal Internet Of Things" and version "1.2.4.2" | - |
Affected
| ||||||
Hp Search vendor "Hp" | Universal Internet Of Things Search vendor "Hp" for product "Universal Internet Of Things" | 1.4.0 Search vendor "Hp" for product "Universal Internet Of Things" and version "1.4.0" | - |
Affected
| ||||||
Hp Search vendor "Hp" | Universal Internet Of Things Search vendor "Hp" for product "Universal Internet Of Things" | 1.4.1 Search vendor "Hp" for product "Universal Internet Of Things" and version "1.4.1" | - |
Affected
| ||||||
Hp Search vendor "Hp" | Universal Internet Of Things Search vendor "Hp" for product "Universal Internet Of Things" | 1.4.2 Search vendor "Hp" for product "Universal Internet Of Things" and version "1.4.2" | - |
Affected
| ||||||
Hp Search vendor "Hp" | Universal Internet Of Things Search vendor "Hp" for product "Universal Internet Of Things" | 1.5 Search vendor "Hp" for product "Universal Internet Of Things" and version "1.5" | - |
Affected
|