« Volver al listado

CVE-2018-7111

Estado: ModificadaMedia (5.3)—

A remote unauthorized access vulnerability was identified in HPE UIoT versions 1.5, 1.4.0, 1.4.1, 1.4.2, 1.2.4.2. Specifically, there is a malfunction identified in some section of the DSM portal and some DSM APIs. The impact of the malfunction is that the info can be changed by other users.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2018-7111",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security-alert@hpe.com",
      "affectedData": [
        {
          "vendor": "Hewlett Packard Enterprise",
          "product": "HPE UIoT",
          "versions": [
            {
              "status": "affected",
              "version": "versions 1.5,1.4.0, 1.4.1, 1.4.2, 1.2.4.2"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-10-17T13:29:00.723",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/105704",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "security-alert@hpe.com"
    },
    {
      "url": "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03891en_us",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security-alert@hpe.com"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/151691",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "nvd@nist.gov"
    },
    {
      "url": "http://www.securityfocus.com/bid/105704",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03891en_us",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A remote unauthorized access vulnerability was identified in HPE UIoT versions 1.5, 1.4.0, 1.4.1, 1.4.2, 1.2.4.2. Specifically, there is a malfunction identified in some section of the DSM portal and some DSM APIs. The impact of the malfunction is that the info can be changed by other users."
    },
    {
      "lang": "es",
      "value": "Se ha identificado una vulnerabilidad de acceso remoto no autorizado en HPE UIoT en versiones 1.5, 1.4.0, 1.4.1, 1.4.2 y 1.2.4.2. Específicamente, hay un mal funcionamiento identificado en algunas secciones del portal DSM y algunas API DSM. El impacto de este mal funcionamiento es que otros usuarios pueden modificar esta información."
    }
  ],
  "lastModified": "2026-06-17T02:02:40.920",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:hp:universal_internet_of_things:1.2.4.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9122AE4B-9F75-499D-AAC3-397F8BFD5FC7"
            },
            {
              "criteria": "cpe:2.3:a:hp:universal_internet_of_things:1.4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2F3BCE1E-0F75-4CB4-8752-533C4E53E10B"
            },
            {
              "criteria": "cpe:2.3:a:hp:universal_internet_of_things:1.4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9FFF3936-D055-4621-A469-BFF3D6801949"
            },
            {
              "criteria": "cpe:2.3:a:hp:universal_internet_of_things:1.4.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D7FE59A6-8B7E-468F-AD75-D139C48FAE78"
            },
            {
              "criteria": "cpe:2.3:a:hp:universal_internet_of_things:1.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "26A57743-E49C-403E-9F06-9EFFABEDB2AD"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-alert@hpe.com"
}