PT-2023-6314 · Hewlett Packard · Hp Thinupdate Utility

Published

2023-10-13

·

Updated

2023-10-19

·

CVE-2023-4499

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions HP ThinUpdate utility (also known as HP Recovery Image and Software Download Tool) (affected versions not specified)
Description A potential security issue has been identified in the HP ThinUpdate utility, which may lead to information disclosure. This issue is related to insufficient protection of internal data. An attacker, acting remotely, could exploit this issue to gain unauthorized access to protected information. HP is releasing mitigation for the potential issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

BDU:2023-07025
CVE-2023-4499

Affected Products

Hp Thinupdate Utility