Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2019-11990

EPSS 0.39% · P60
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2019-11990

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Security vulnerabilities in HPE UIoT versions 1.6, 1.5, 1.4.2, 1.4.1, 1.4.0, and 1.2.4.2 could allow unauthorized remote access and access to sensitive data. HPE has addressed this issue in HPE UIoT: * For customers with release UIoT 1.6, fixes are made available with 1.6 RP603 * For customers with release UIoT 1.5, fixes are made available with 1.5 RP503 HF3 * For customers with release older than 1.5, such as 1.4.0, 1.4.1, 1.4.2 and 1.2.4.2, the resolution will be to upgrade to 1.5 RP503 HF3 or 1.6 RP603 Customers are requested to upgrade to the updated versions or contact HPE support for further assistance.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
HPE UIoT 访问控制错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
HPE UIoT是美国惠普企业公司(Hewlett Packard Enterprise,HPE)的一套通用物联网平台。该平台具有数据分析、货币安全和同步管理等功能。 HPE UIoT中存在访问控制错误漏洞。攻击者可利用该漏洞未授权访问敏感数据。以下产品及版本受到影响:HPE UIoT 1.6版本,1.5版本,1.4.2版本,1.4.1版本,1.4.0版本,1.2.4.2版本。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-HPE IOT and GCP 1.6, 1.5, 1.4.0, 1,4,1, 1.4.2, 1.2.4.2 -

II. Public POCs for CVE-2019-11990

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2019-11990

登录查看更多情报信息。

Same Patch Batch · n/a · 2019-07-19 · 36 CVEs total

CVE-2019-1579Palo Alto Networks PAN-OS 输入验证错误漏洞
CVE-2019-12193H3C H3Cloud OS SQL注入漏洞
CVE-2019-11553Code42 Software Code42 for Enterprise 访问控制错误漏洞
CVE-2018-17792MDaemon Webmail 跨站请求伪造漏洞
CVE-2019-12453Microstrategy Web 跨站脚本漏洞
CVE-2019-12820Jisiwei i3 信任管理问题漏洞
CVE-2019-12821Jisiwei i3 安全特征问题漏洞
CVE-2019-13989dpic 缓冲区错误漏洞
CVE-2019-13991Arduino 注入漏洞
CVE-2015-7882Authentication bypass when using LDAP authentication in MongoDB Enterprise Server
CVE-2019-11989HPE IceWall SSO Agent Option和IceWall MFA 输入验证错误漏洞
CVE-2019-12725Zeroshell 操作系统命令注入漏洞
CVE-2019-13569WordPress Icegram Email Subscribers & Newsletters插件SQL注入漏洞
CVE-2019-9228多款AudioCodes产品资源管理错误漏洞
CVE-2019-12815ProFTPD 访问控制错误漏洞
CVE-2019-9229多款AudioCodes产品信任管理问题漏洞
CVE-2018-17210PrinterOn Central Print Services 授权问题漏洞
CVE-2019-12934WordPress wp-code-highlightjs插件跨站请求伪造漏洞
CVE-2019-11552Code42 Software CrashPlan for Small Business 代码注入漏洞
CVE-2019-13970antSword 跨站脚本漏洞

Showing top 20 of 36 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2019-11990

No comments yet


Leave a comment