CVE-2019-12000 Vulnerability Details

  /     /     /  

CVE-2019-12000 Metadata Quick Info

CVE Published: 17/07/2020 | CVE Updated: 04/08/2024 | CVE Year: 2019
Source: hpe | Vendor: HPE | Product: HPE MSE Msg Gw application E-LTU
Status : PUBLISHED

CVE-2019-12000 Description

HPE has found a potential Remote Access Restriction Bypass in HPE MSE Msg Gw application E-LTU prior to version 3.2 when HTTPS is used between the USSD and an external USSD service logic application. Update to version 3.2 and update the HTTPS configuration as described in the HPE MSE Messaging Gateway Configuration and Operations Guide.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: remote access restriction bypass; remote user validation failure
Source: HPE

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).