CVE-2011-0890
HP Discovery & Dependency Mapping Inventory (DDMI) 7.50, 7.51, 7.60, 7.61, 7.70, and 9.30 launches the Windows SNMP service with its default configuration, which allows remote attackers to obtain potentially sensitive information or have unspecified…
Does this matter?
Lower severity and a low EPSS score (2.54%). Track it; it rarely justifies an emergency change on its own.
Description
HP Discovery & Dependency Mapping Inventory (DDMI) 7.50, 7.51, 7.60, 7.61, 7.70, and 9.30 launches the Windows SNMP service with its default configuration, which allows remote attackers to obtain potentially sensitive information or have unspecified other impact by leveraging the public read community.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.54% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- hp/discovery\&dependency mapping inventory
- Source
- hp-security-alert@hp.com
References
- http://marc.info/?l=bugtraq&m=130082163516878&w=2Vendor Advisory
- http://securityreason.com/securityalert/8163
- http://securitytracker.com/id?1025239
- http://www.securityfocus.com/bid/46981
- http://www.vupen.com/english/advisories/2011/0755
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66242
- http://marc.info/?l=bugtraq&m=130082163516878&w=2Vendor Advisory
- http://securityreason.com/securityalert/8163
- http://securitytracker.com/id?1025239
- http://www.securityfocus.com/bid/46981
- http://www.vupen.com/english/advisories/2011/0755
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66242
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.