SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-24623

A potential security vulnerability has been identified in Hewlett Packard Enterprise Universal API Framework.

MEDIUM 6.5EPSS 0.95%

Does this matter?

Lower severity and a low EPSS score (0.95%). Track it; it rarely justifies an emergency change on its own.

Description

A potential security vulnerability has been identified in Hewlett Packard Enterprise Universal API Framework. The vulnerability could be remotely exploited to allow SQL injection in HPE Universal API Framework for VMware Esxi v2.5.2 and HPE Universal API Framework for Microsoft Hyper-V (VHD).

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
0.95% probability · 59th percentile
CISA KEV
Not listed
Weakness
CWE-89
Affected
hpe/universal api framework
Source
security-alert@hpe.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.