CRITICAL

CVE-2020-7136

CVSS v3

9.8

CRITICAL

EPSS Score

73.1%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access. Hewlett Packard Enterprise has provided a software update to resolve this vulnerability in HPE Smart Update Manager (SUM) prior to 8.5.6. Please visit the HPE Support Center at https://support.hpe.com/hpesc/public/home to download the latest version of HPE Smart Update Manager (SUM). Download the latest version of HPE Smart Update Manager (SUM) or download the latest Service Pack For ProLiant (SPP).

Technical details

Published
4/30/2020

Frequently asked questions

What is CVE-2020-7136?

A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access. Hewlett Packard Enterprise has provided a software update to resolve this vulnerability in HPE Smart Update Manager (SUM) prior to 8.5.6. Please visit the HPE Support Center at https://support.hpe.com/hpesc/public/home to download the latest version of HPE Smart Update Manager (SUM). Download the latest version of HPE Smart Update Manager (SUM) or download the latest Service Pack For ProLiant (SPP).

Is CVE-2020-7136 actively exploited?

Active exploitation of CVE-2020-7136 has not been confirmed. The EPSS score is 73.1%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2020-7136?

CVE-2020-7136 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2020-7136 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.