CVE-2017-14349: Critical severity hp sitescope vulnerability
Published Sep 29, 2017
·Updated
An authentication vulnerability in HPE SiteScope product versions 11.2x and 11.3x, allows read-only accounts to view all SiteScope interfaces and monitors, potentially exposing sensitive data.
Affected Software
11 affected components
HP SiteScope=11.20
HP SiteScope=11.21
HP SiteScope=11.22
HP SiteScope=11.23
HP SiteScope=11.24
HP SiteScope=11.24.391
HP SiteScope=11.30
HP SiteScope=11.30.521
HP SiteScope=11.31
HP SiteScope=11.32
HP SiteScope=11.33
Event History
Sep 29, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14349?
CVE-2017-14349 has a medium severity level, as it allows read-only accounts to access sensitive data.
2
How do I fix CVE-2017-14349?
To fix CVE-2017-14349, you should upgrade HPE SiteScope to a version that addresses this authentication vulnerability.
3
Which versions of HPE SiteScope are affected by CVE-2017-14349?
CVE-2017-14349 affects HPE SiteScope versions 11.20 to 11.33.
4
What type of vulnerability is CVE-2017-14349?
CVE-2017-14349 is an authentication vulnerability that affects user account permissions.
5
Who is impacted by CVE-2017-14349?
Organizations using affected versions of HPE SiteScope with read-only accounts may be impacted by CVE-2017-14349.