Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2007-4590


The get_system_info command in Ignite-UX C.7.0 through C.7.3, and DynRootDisk (DRD) A.1.0.16.417 through A.2.0.0.592, on HP-UX B.11.11, B.11.23, and B.11.31 does not inform local users of networking changes made by the command, which has unknown impact and attack vectors.


Published

2007-08-29T01:17:00.000

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 3.3 (LOW)

CVSSv2 Vector

AV:L/AC:M/Au:N/C:N/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.4

Impact Score

4.9

Weaknesses
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System hp hp-ux 11.23 No
Operating System hp hp-ux 11.31 No
Application hp dynrootdisk a.1.0.16.417 Yes
Application hp dynrootdisk a.1.0.18.245 Yes
Application hp dynrootdisk a.1.1.0.344 Yes
Application hp dynrootdisk a.2.0.0.592 Yes
Operating System hp hp-ux 11.11 Yes
Operating System hp hp-ux 11.23 Yes
Operating System hp hp-ux 11.31 Yes
Application hp ignite-ux c.7.0.212 Yes
Application hp ignite-ux c.7.1.92 Yes
Application hp ignite-ux c.7.2.93 Yes
Application hp ignite-ux c.7.3.144 Yes

References