A remote unauthorized access vulnerability was identified in HPE UIoT versions 1.5, 1.4.0, 1.4.1, 1.4.2, 1.2.4.2. Specifically, there is a malfunction identified in some section of the DSM portal and some DSM APIs. The impact of the malfunction is that the info can be changed by other users.
2018-10-17T13:29:00.723
2024-11-21T04:11:39.657
Modified
CVSSv3.0: 5.3 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:P/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | hp | universal_internet_of_things | 1.2.4.2 | Yes |
Application | hp | universal_internet_of_things | 1.4.0 | Yes |
Application | hp | universal_internet_of_things | 1.4.1 | Yes |
Application | hp | universal_internet_of_things | 1.4.2 | Yes |
Application | hp | universal_internet_of_things | 1.5 | Yes |