CVE-2024-28893
Status: AnalyzedHigh (7.7)—
Certain HP software packages (SoftPaqs) are potentially vulnerable to arbitrary code execution when the SoftPaq configuration file has been modified after extraction. HP has released updated software packages (SoftPaqs).
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
- Base score: 7.7
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.28%
- Percentile among all scored CVEs: 19
- Score date: 10/11/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-94
References
Raw JSON (NVD)
Show
{
"id": "CVE-2024-28893",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-28893",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-05-01T21:04:05.999578Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 7.7,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 1.1
}
]
},
"affected": [
{
"source": "hp-security-alert@hp.com",
"affectedData": [
{
"vendor": "HP Inc.",
"product": "HP software packages (SoftPaqs)",
"versions": [
{
"status": "affected",
"version": "See HP Security Bulletin reference for affected versions."
}
],
"defaultStatus": "unknown"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:hp:softpaqs:-:*:*:*:*:*:*:*"
],
"vendor": "hp",
"product": "softpaqs",
"versions": [
{
"status": "affected",
"version": "-"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-05-01T16:15:07.553",
"references": [
{
"url": "https://support.hp.com/us-en/document/ish_10502451-10502508-16/hpsbhf03931",
"tags": [
"Vendor Advisory"
],
"source": "hp-security-alert@hp.com"
},
{
"url": "https://support.hp.com/us-en/document/ish_10502451-10502508-16/hpsbhf03931",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-94"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Certain HP software packages (SoftPaqs) are potentially vulnerable to arbitrary code execution when the SoftPaq configuration file has been modified after extraction. HP has released updated software packages (SoftPaqs)."
},
{
"lang": "es",
"value": "Ciertos paquetes de software de HP (SoftPaqs) son potencialmente vulnerables a la ejecución de código arbitrario cuando el archivo de configuración del SoftPaq se modifica después de la extracción. HP ha lanzado paquetes de software actualizados (SoftPaqs)."
}
],
"lastModified": "2026-06-17T07:21:59.020",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hp:softpaqs:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C7F94FBD-3773-4542-827E-10619A865D19"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "hp-security-alert@hp.com"
}