VulnerabilityModified
CVE-2017-5799
A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found.
HIGH 8.8EPSS 15.2%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 15.2%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP versions prior to 3.4.2 RP201 (for OCMP 3.x), all versions prior to 4.4.7 RP702 (for OCMP 4.x).
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 15.23% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74
- Affected
- hp/opencall media platform
- Source
- security-alert@hpe.com
References
- http://www.securityfocus.com/bid/98013Third Party Advisory, VDB Entry
- https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbgn03686en_usVendor Advisory
- https://www.exploit-db.com/exploits/41927/Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/98013Third Party Advisory, VDB Entry
- https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbgn03686en_usVendor Advisory
- https://www.exploit-db.com/exploits/41927/Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.