CVE-2008-1662
Unspecified vulnerability in the HP System Administration Manager (SAM) on HP-UX B.11.11 and B.11.23, when used to configure NFS, might allow remote attackers to read or modify arbitrary files, related to an "empty systems list."
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.42%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Unspecified vulnerability in the HP System Administration Manager (SAM) on HP-UX B.11.11 and B.11.23, when used to configure NFS, might allow remote attackers to read or modify arbitrary files, related to an "empty systems list."
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 4.42% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-16
- Affected
- hp/hp-ux · hp/system administration manager
- Source
- cve@mitre.org
References
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01367453
- http://secunia.com/advisories/31309Vendor Advisory
- http://securitytracker.com/id?1020580
- http://www.securityfocus.com/bid/30449
- http://www.vupen.com/english/advisories/2008/2258
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44119
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5814
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01367453
- http://secunia.com/advisories/31309Vendor Advisory
- http://securitytracker.com/id?1020580
- http://www.securityfocus.com/bid/30449
- http://www.vupen.com/english/advisories/2008/2258
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44119
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5814
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.