SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-7111

A remote unauthorized access vulnerability was identified in HPE UIoT versions 1.5, 1.4.0, 1.4.1, 1.4.2, 1.2.4.2.

MEDIUM 5.3EPSS 5.27%

Does this matter?

Lower severity and a low EPSS score (5.27%). Track it; it rarely justifies an emergency change on its own.

Description

A remote unauthorized access vulnerability was identified in HPE UIoT versions 1.5, 1.4.0, 1.4.1, 1.4.2, 1.2.4.2. Specifically, there is a malfunction identified in some section of the DSM portal and some DSM APIs. The impact of the malfunction is that the info can be changed by other users.

CVSS 3.0
5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS
5.27% probability · 92th percentile
CISA KEV
Not listed
Affected
hp/universal internet of things
Source
security-alert@hpe.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.