Vulnerability Name: | CVE-2007-4931 (CCN-36615) | ||||||||
Assigned: | 2007-09-10 | ||||||||
Published: | 2007-09-10 | ||||||||
Updated: | 2011-03-08 | ||||||||
Summary: | HP System Management Homepage (SMH) for Windows, when used in conjunction with HP Version Control Agent or Version Control Repository Manager, leaves old OpenSSL software active after an OpenSSL update, which has unknown impact and attack vectors, probably related to previous vulnerabilities for OpenSSL. | ||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N) 1.7 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:W/RC:C)
1.5 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:W/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-4931 Source: CCN Type: HP Security Bulletin HPSBMA02258 SSRT071470 HP System Management Homepage (SMH) for Windows, Incomplete Update Installation Source: HP Type: UNKNOWN SSRT071470 Source: OSVDB Type: UNKNOWN 45941 Source: CCN Type: SECTRACK ID: 1018696 HP System Management Homepage May Not Properly Complete Security Updates Source: SECTRACK Type: UNKNOWN 1018696 Source: CCN Type: OSVDB ID: 45941 HP System Management Homepage (SMH) for Windows OpenSSL Version Regression Source: BID Type: UNKNOWN 25675 Source: CCN Type: BID-25675 HP System Management Homepage Incomplete Update Installation Weakness Source: XF Type: UNKNOWN hp-smh-openssl-weak-security(36615) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |