CVE-2018-7111
Last modified
CVE-2018-7111 is a vulnerability of currently unknown severity. A remote unauthorized access vulnerability was identified in HPE UIoT versions 1.5, 1.4.0, 1.4.1, 1.4.2, 1.2.4.2. Specifically, there is a malfunction identified in some section of the DSM portal and some DSM APIs. EPSS estimates a 5.27% chance of exploitation in the next 30 days.
Description
A remote unauthorized access vulnerability was identified in HPE UIoT versions 1.5, 1.4.0, 1.4.1, 1.4.2, 1.2.4.2. Specifically, there is a malfunction identified in some section of the DSM portal and some DSM APIs. The impact of the malfunction is that the info can be changed by other users.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hp | Universal Internet Of Things | 1.2.4.2 |
| Hp | Universal Internet Of Things | 1.4.0 |
| Hp | Universal Internet Of Things | 1.4.1 |
| Hp | Universal Internet Of Things | 1.4.2 |
| Hp | Universal Internet Of Things | 1.5 |
References
- http://www.securityfocus.com/bid/105704Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/151691Third Party Advisory
- http://www.securityfocus.com/bid/105704Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-7111?
How severe is CVE-2018-7111?
How do I fix CVE-2018-7111?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-7105A security vulnerability in HPE Integrated Lights-Out 5 (iLO…
- CVE-2018-7106Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2018-7107A potential security vulnerability has been identified in HP…
- CVE-2018-7108HPE StorageWorks XP7 Automation Director (AutoDir) version 8…
- CVE-2018-7109HPE has addressed a remote arbitrary file modification vulne…
- CVE-2018-7110A remote unauthorized disclosure of information vulnerabilit…
- CVE-2018-7112The HPE-provided Windows firmware installer for certain Gen9…
- CVE-2018-7113A security vulnerability in HPE Integrated Lights-Out 5 (iLO…
- CVE-2018-7114HPE Intelligent Management Center (IMC) prior to IMC PLAT 7.…
- CVE-2018-7115HPE Intelligent Management Center (IMC) prior to IMC PLAT 7.…
- CVE-2018-7116HPE Intelligent Management Center (IMC) prior to IMC PLAT 7.…
- CVE-2018-7117A remote Cross-Site Scripting in HPE iLO 5 Web User Interfac…
Are you affected by CVE-2018-7111?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
