« Volver al listado

CVE-2018-7107

Estado: ModificadaAlta (8.8)—

A potential security vulnerability has been identified in HPE Device Entitlement Gateway (DEG) v3.2.4, v3.3 and v3.3.1. The vulnerability could be remotely exploited to allow local SQL injection and elevation of privilege.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2018-7107",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-alert@hpe.com",
      "affectedData": [
        {
          "vendor": "Hewlett Packard Enterprise",
          "product": "HPE Device Entitlement Gateway (DEG)",
          "versions": [
            {
              "status": "affected",
              "version": "v3.2.4, v3.3 and v3.3.1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-09-27T18:29:01.017",
  "references": [
    {
      "url": "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn03889en_us",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security-alert@hpe.com"
    },
    {
      "url": "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn03889en_us",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A potential security vulnerability has been identified in HPE Device Entitlement Gateway (DEG) v3.2.4, v3.3 and v3.3.1. The vulnerability could be remotely exploited to allow local SQL injection and elevation of privilege."
    },
    {
      "lang": "es",
      "value": "Se ha identificado una potencial vulnerabilidad de seguridad en HPE Device Entitlement Gateway (DEG) v3.2.4, v3.3 y v3.3.1. La vulnerabilidad se podría explotar de forma remota para permitir una inyección SQL local y la elevación de privilegios."
    }
  ],
  "lastModified": "2026-06-17T02:02:40.527",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:hpe:device_entitlement_gateway:3.2.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9A4A17AC-EEBE-48BE-8554-CEAADF9D25BC"
            },
            {
              "criteria": "cpe:2.3:a:hpe:device_entitlement_gateway:3.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B0198DF6-15F5-466A-98A3-6B2EBD8DEB60"
            },
            {
              "criteria": "cpe:2.3:a:hpe:device_entitlement_gateway:3.3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2DE58963-B44F-4685-B8BF-B2784F78D364"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-alert@hpe.com"
}