Improper Control of Generation of Code ('Code Injection') (CWE-94)
HP Security Manager is potentially vulnerable to Remote Code Execution as a result of code vulnerability within the product's solution open-source libraries. This vulnerability is associated with Improper Control of Generation of Code ('Code Injection'). The vulnerability has a CVSS v3.1 base score of 9.8, indicating a critical severity level. It affects HP Security Manager version 3.11.
The vulnerability allows for remote code execution with high impact on confidentiality, integrity, and availability. An attacker can potentially execute arbitrary code on the affected system without requiring user interaction or privileges. This could lead to complete system compromise, unauthorized access to sensitive data, and disruption of services. The attack vector is network-based, with low attack complexity and no required privileges or user interaction.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
As of the provided information, a patch is available. HP has released a fix for this vulnerability, which can be found at https://support.hp.com/us-en/document/ish_11074404-11074432-16/.
While no specific mitigation strategies are provided in the given information, general recommendations for high-severity vulnerabilities like this often include: 1. Implement network segmentation to limit access to affected systems. 2. Monitor for suspicious activities or unauthorized access attempts. 3. Apply principle of least privilege to limit potential impact. 4. Keep systems and software up-to-date with the latest security patches when they become available. 5. Consider temporarily disabling the affected product if possible until the patch is applied. 6. Regularly check for updates from HP regarding this vulnerability. 7. Apply the available patch from HP as soon as possible.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NVD published the first details for CVE-2024-7720
Feedly found the first article mentioning CVE-2024-7720. See article
Feedly estimated the CVSS score as HIGH
EPSS Score was set to: 0.04% (Percentile: 9.5%)