« Volver al listado

CVE-2019-19539

Estado: ModificadaMedia (5.5)—

An issue was discovered in Idelji Web ViewPoint H01ABO-H01BY and L01ABP-L01ABZ, Web ViewPoint Plus H01AAG-H01AAQ and L01AAH-L01AAR, and Web ViewPoint Enterprise H01-H01AAE and L01-L01AAF. By reading ADB or AADB file content within the Installation subvolume, a Guardian user can discover the password of the group.user or alias who acknowledges events from the WVP Events screen.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-19539",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.1,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-01-27T19:15:11.160",
  "references": [
    {
      "url": "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03981en_us",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03981en_us",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-522"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An issue was discovered in Idelji Web ViewPoint H01ABO-H01BY and L01ABP-L01ABZ, Web ViewPoint Plus H01AAG-H01AAQ and L01AAH-L01AAR, and Web ViewPoint Enterprise H01-H01AAE and L01-L01AAF. By reading ADB or AADB file content within the Installation subvolume, a Guardian user can discover the password of the group.user or alias who acknowledges events from the WVP Events screen."
    },
    {
      "lang": "es",
      "value": "Se detectó un problema en Idelji Web ViewPoint versiones H01ABO-H01BY y L01ABP-L01ABZ, Web ViewPoint Plus versiones H01AAG-H01AAQ y L01AAH-L01AAR y Web ViewPoint Enterprise versiones H01-H01AAE y L01-L01AAF. Mediante la lectura del contenido del archivo ADB o AADB dentro del subvolumen Installation, un usuario Guardian puede descubrir la contraseña de group.user o el alias de quien reconoce los eventos desde la pantalla WVP Events."
    }
  ],
  "lastModified": "2026-06-17T02:26:50.663",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:hp:web_viewpoint_t0320:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "09E6FA05-C08A-48C6-83D0-539CC3582E3B",
              "versionEndIncluding": "t0320h01\\^aby",
              "versionStartIncluding": "t0320h01\\^abo"
            },
            {
              "criteria": "cpe:2.3:a:hp:web_viewpoint_t0320:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3AC80F89-C8A3-4992-87FB-ED9E5BC2B8F2",
              "versionEndIncluding": "t0320l01\\^abz",
              "versionStartIncluding": "t0320l01\\^abp"
            },
            {
              "criteria": "cpe:2.3:a:hp:web_viewpoint_t0952:*:*:*:*:plus:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7D6FEE50-D889-4CB7-A915-CB635A98D601",
              "versionEndIncluding": "t0952h01\\^aaq",
              "versionStartIncluding": "t0952h01\\^aag"
            },
            {
              "criteria": "cpe:2.3:a:hp:web_viewpoint_t0952:*:*:*:*:plus:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "569BB034-91E2-4A50-9905-9C56A7B5269A",
              "versionEndIncluding": "t0952l01\\^aar",
              "versionStartIncluding": "t0952l01\\^aah"
            },
            {
              "criteria": "cpe:2.3:a:hp:web_viewpoint_t0986:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8C7B1372-EFBF-414D-90C6-A03D07F05408",
              "versionEndIncluding": "t0320l01\\^abz",
              "versionStartIncluding": "t0320l01\\^abp"
            },
            {
              "criteria": "cpe:2.3:a:hp:web_viewpoint_t0986:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FB7322B4-F7DD-4BD5-AC2A-B4319FBD4085",
              "versionEndIncluding": "t0986h01\\^aae",
              "versionStartIncluding": "t0986h01"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}