CVE-2007-4931
HP System Management Homepage (SMH) for Windows, when used in conjunction with HP Version Control Agent or Version Control Repository Manager, leaves old OpenSSL software active after an OpenSSL update, which has unknown impact and attack vectors,…
Does this matter?
Lower severity and a low EPSS score (0.48%). Track it; it rarely justifies an emergency change on its own.
Description
HP System Management Homepage (SMH) for Windows, when used in conjunction with HP Version Control Agent or Version Control Repository Manager, leaves old OpenSSL software active after an OpenSSL update, which has unknown impact and attack vectors, probably related to previous vulnerabilities for OpenSSL.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 0.48% probability · 40th percentile
- CISA KEV
- Not listed
- Affected
- hp/system management homepage
- Source
- cve@mitre.org
References
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01164065
- http://osvdb.org/45941
- http://securitytracker.com/id?1018696
- http://www.securityfocus.com/bid/25675
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01164065
- http://osvdb.org/45941
- http://securitytracker.com/id?1018696
- http://www.securityfocus.com/bid/25675
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.