« Volver al listado

CVE-2024-28893

Estado: AnalizadaAlta (7.7)—

Ciertos paquetes de software de HP (SoftPaqs) son potencialmente vulnerables a la ejecución de código arbitrario cuando el archivo de configuración del SoftPaq se modifica después de la extracción. HP ha lanzado paquetes de software actualizados (SoftPaqs).

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-28893",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-28893",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-05-01T21:04:05.999578Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 7.7,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 1.1
      }
    ]
  },
  "affected": [
    {
      "source": "hp-security-alert@hp.com",
      "affectedData": [
        {
          "vendor": "HP Inc.",
          "product": "HP software packages (SoftPaqs)",
          "versions": [
            {
              "status": "affected",
              "version": "See HP Security Bulletin reference for affected versions."
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:hp:softpaqs:-:*:*:*:*:*:*:*"
          ],
          "vendor": "hp",
          "product": "softpaqs",
          "versions": [
            {
              "status": "affected",
              "version": "-"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-05-01T16:15:07.553",
  "references": [
    {
      "url": "https://support.hp.com/us-en/document/ish_10502451-10502508-16/hpsbhf03931",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "hp-security-alert@hp.com"
    },
    {
      "url": "https://support.hp.com/us-en/document/ish_10502451-10502508-16/hpsbhf03931",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-94"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Certain HP software packages (SoftPaqs) are potentially vulnerable to arbitrary code execution when the SoftPaq configuration file has been modified after extraction. HP has released updated software packages (SoftPaqs)."
    },
    {
      "lang": "es",
      "value": "Ciertos paquetes de software de HP (SoftPaqs) son potencialmente vulnerables a la ejecución de código arbitrario cuando el archivo de configuración del SoftPaq se modifica después de la extracción. HP ha lanzado paquetes de software actualizados (SoftPaqs)."
    }
  ],
  "lastModified": "2026-06-17T07:21:59.020",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:hp:softpaqs:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C7F94FBD-3773-4542-827E-10619A865D19"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "hp-security-alert@hp.com"
}