HP Device Manager Command Injection Vulnerability

HP Device Manager Command Injection Vulnerability

According to the vulnerability that has been released on June 20, HP Device Manager (prior to HPDM 5.0.10) could potentially allow to a command injection and/or elevation of privileges

HP Device Manager Command Injection Vulnerability

Affected Systems

cpe:2.3:a:hp:hp_device_manager:5.0:-:*:*:*:*:*:*
cpe:2.3:a:hp:hp_device_manager:5.0:sp1:*:*:*:*:*:*
cpe:2.3:a:hp:hp_device_manager:5.0:sp2:*:*:*:*:*:*
cpe:2.3:a:hp:hp_device_manager:5.0.3:*:*:*:*:*:*:*
cpe:2.3:a:hp:hp_device_manager:5.0.4:*:*:*:*:*:*:*
cpe:2.3:a:hp:hp_device_manager:5.0.5:*:*:*:*:*:*:*
cpe:2.3:a:hp:hp_device_manager:5.0.6:*:*:*:*:*:*:*
cpe:2.3:a:hp:hp_device_manager:5.0.7:*:*:*:*:*:*:*
cpe:2.3:a:hp:hp_device_manager:5.0.7.1:*:*:*:*:*:*:*
cpe:2.3:a:hp:hp_device_manager:5.0.8:*:*:*:*:*:*:*
cpe:2.3:a:hp:hp_device_manager:5.0.9:*:*:*:*:*:*:*

IoC’s

-

Recommended Solution(s)

-

Mitigations

-

CVE / CWE

CVE-2023-26295

Related Website(s)

* Vulnerabilities with a CVSS 3.1 score between 7.0 and 8.9 are evaluated to be “high” whereas vulnerabilities with a CVSS 3.1 score between 9.0 and 10.0 are evaluated to be “critical”.