6.6
CVE-2019-12000
- EPSS 0.31%
- Published 17.07.2020 22:15:11
- Last modified 21.11.2024 04:22:08
- Source security-alert@hpe.com
- Teams watchlist Login
- Open Login
HPE has found a potential Remote Access Restriction Bypass in HPE MSE Msg Gw application E-LTU prior to version 3.2 when HTTPS is used between the USSD and an external USSD service logic application. Update to version 3.2 and update the HTTPS configuration as described in the HPE MSE Messaging Gateway Configuration and Operations Guide.
Data is provided by the National Vulnerability Database (NVD)
Hp ≫ Mse Msg Gw Application E-ltu Version < 3.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.31% | 0.534 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.6 | 0.7 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 5.4 | 5.5 | 6.4 |
AV:N/AC:M/Au:M/C:P/I:P/A:P
|
CWE-295 Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.