CVE-2010-3011

UnknownEPSS 3.60%

Last modified

CVE-2010-3011 is a vulnerability of currently unknown severity. CRLF injection vulnerability in HP System Management Homepage (SMH) before 6.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.. EPSS estimates a 3.60% chance of exploitation in the next 30 days.

Description

CRLF injection vulnerability in HP System Management Homepage (SMH) before 6.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

Metrics

EPSS Probability
3.60%

88.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
HpSystem Management Homepage<= 6.1
HpSystem Management Homepage2.0.0
HpSystem Management Homepage2.0.1
HpSystem Management Homepage2.0.1.104
HpSystem Management Homepage2.0.2
HpSystem Management Homepage2.0.2.106
HpSystem Management Homepage2.1
HpSystem Management Homepage2.1.0-103
HpSystem Management Homepage2.1.0-103\(a\)
HpSystem Management Homepage2.1.0-109
HpSystem Management Homepage2.1.0-118
HpSystem Management Homepage2.1.0.121
HpSystem Management Homepage2.1.1
HpSystem Management Homepage2.1.2
HpSystem Management Homepage2.1.2-127
HpSystem Management Homepage2.1.2.127
HpSystem Management Homepage2.1.3
HpSystem Management Homepage2.1.3.132
HpSystem Management Homepage2.1.4
HpSystem Management Homepage2.1.4-143
HpSystem Management Homepage2.1.4.143
HpSystem Management Homepage2.1.5
HpSystem Management Homepage2.1.5-146
HpSystem Management Homepage2.1.5.146
HpSystem Management Homepage2.1.6
HpSystem Management Homepage2.1.6-156
HpSystem Management Homepage2.1.6.156
HpSystem Management Homepage2.1.7
HpSystem Management Homepage2.1.7-168
HpSystem Management Homepage2.1.7.168
HpSystem Management Homepage2.1.8
HpSystem Management Homepage2.1.8-177
HpSystem Management Homepage2.1.8.179
HpSystem Management Homepage2.1.9
HpSystem Management Homepage2.1.9-178
HpSystem Management Homepage2.1.10
HpSystem Management Homepage2.1.10-186
HpSystem Management Homepage2.1.10.186
HpSystem Management Homepage2.1.11
HpSystem Management Homepage2.1.11-197
HpSystem Management Homepage2.1.11.197A
HpSystem Management Homepage2.1.12-118
HpSystem Management Homepage2.1.12-200
HpSystem Management Homepage2.1.12.201
HpSystem Management Homepage2.1.14.20
HpSystem Management Homepage2.1.15-210
HpSystem Management Homepage2.1.15.210
HpSystem Management Homepage2.2.6
HpSystem Management Homepage2.2.8
HpSystem Management Homepage3.0.0-68

Showing 50 of 60 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2010-3011?
CRLF injection vulnerability in HP System Management Homepage (SMH) before 6.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
How severe is CVE-2010-3011?
Severity scoring for CVE-2010-3011 is pending analysis. The EPSS model estimates a 3.60% probability of exploitation in the next 30 days.
How do I fix CVE-2010-3011?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2010-3011?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST