« Volver al listado

CVE-2017-14349

Estado: ModificadaCrítica (9.8)—

An authentication vulnerability in HPE SiteScope product versions 11.2x and 11.3x, allows read-only accounts to view all SiteScope interfaces and monitors, potentially exposing sensitive data.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-14349",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@opentext.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-09-30T01:29:01.443",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/100989",
      "source": "security@opentext.com"
    },
    {
      "url": "https://softwaresupport.hpe.com/km/KM02948051",
      "source": "security@opentext.com"
    },
    {
      "url": "https://www.auscert.org.au/bulletins/52758",
      "source": "security@opentext.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/100989",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://softwaresupport.hpe.com/km/KM02948051",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.auscert.org.au/bulletins/52758",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-269"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An authentication vulnerability in HPE SiteScope product versions 11.2x and 11.3x, allows read-only accounts to view all SiteScope interfaces and monitors, potentially exposing sensitive data."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de autenticación en las versiones 11.2x y 11.3x de HPE SiteScope permite que las cuentas de sólo lectura vean todas las interfaces y monitores de SiteScope, pudiendo llegar a exponer datos sensibles."
    }
  ],
  "lastModified": "2026-06-17T01:06:00.097",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:hp:sitescope:11.20:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8172205D-C9CE-487E-BF67-33A46EBF056E"
            },
            {
              "criteria": "cpe:2.3:a:hp:sitescope:11.21:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5F8F86F8-D697-44B8-9216-2319EF7A76D6"
            },
            {
              "criteria": "cpe:2.3:a:hp:sitescope:11.22:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5290D701-53C2-4C14-B380-F9DE30DA57D1"
            },
            {
              "criteria": "cpe:2.3:a:hp:sitescope:11.23:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3D3D0E42-4BC5-4109-A069-5E1A79A13051"
            },
            {
              "criteria": "cpe:2.3:a:hp:sitescope:11.24:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ABE7D552-5C3F-4B3D-A7B3-AE9D4AD0FAC7"
            },
            {
              "criteria": "cpe:2.3:a:hp:sitescope:11.24.391:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C737A71B-03DF-4436-ACE5-43D47E8C7138"
            },
            {
              "criteria": "cpe:2.3:a:hp:sitescope:11.30:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9F02A47A-24BB-42CA-AC9C-D3A7B2FECEA3"
            },
            {
              "criteria": "cpe:2.3:a:hp:sitescope:11.30.521:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C06DD563-7712-4CC4-AD78-27F534003479"
            },
            {
              "criteria": "cpe:2.3:a:hp:sitescope:11.31:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "230FF2E9-DEDC-4B99-BC2B-7D2488423596"
            },
            {
              "criteria": "cpe:2.3:a:hp:sitescope:11.32:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "027F6746-2AA5-41E8-BE67-A2CAAFEA5CA7"
            },
            {
              "criteria": "cpe:2.3:a:hp:sitescope:11.33:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "779FEDAE-F5D9-4055-A275-FD70C6C93F73"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@opentext.com"
}