5.5

CVE-2019-19539

An issue was discovered in Idelji Web ViewPoint H01ABO-H01BY and L01ABP-L01ABZ, Web ViewPoint Plus H01AAG-H01AAQ and L01AAH-L01AAR, and Web ViewPoint Enterprise H01-H01AAE and L01-L01AAF. By reading ADB or AADB file content within the Installation subvolume, a Guardian user can discover the password of the group.user or alias who acknowledges events from the WVP Events screen.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hp ≫ Web Viewpoint T0320 Version >= t0320h01\^abo <= t0320h01\^aby
Hp ≫ Web Viewpoint T0320 Version >= t0320l01\^abp <= t0320l01\^abz
Hp ≫ Web Viewpoint T0952 SwEdition plus Version >= t0952h01\^aag <= t0952h01\^aaq
Hp ≫ Web Viewpoint T0952 SwEdition plus Version >= t0952l01\^aah <= t0952l01\^aar
Hp ≫ Web Viewpoint T0986 SwEdition enterprise Version >= t0320l01\^abp <= t0320l01\^abz
Hp ≫ Web Viewpoint T0986 SwEdition enterprise Version >= t0986h01 <= t0986h01\^aae
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.43% 0.342
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE-522 Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03981en_us
Vendor Advisory