Severity
8.1HIGH
EPSS
0.3%
top 45.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 7
Latest updateMay 17

Description

HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to modify data or cause a denial of service via unspecified vectors.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:HExploitability: 2.8 | Impact: 5.2

Affected Packages1 packages

NVDhp/network_node_manager_i6 versions+5

Patches

🔴Vulnerability Details

8
GHSA
GHSA-jmqg-pw7j-4mfv: HPE Network Node Manager i (NNMi) 92022-05-17
GHSA
Downloads Resources over HTTP in node-bsdiff-android2018-09-18
OSV
zsh vulnerabilities2018-03-08
OSV
erlang vulnerabilities2018-02-14
OSV
pillow vulnerabilities2017-03-13

💥Exploits & PoCs

2
Exploit-DB
Sun Secure Global Desktop and Oracle Global Desktop 4.61.915 - Command Injection (Shellshock)2016-06-06
Exploit-DB
HP Data Protector A.09.00 - Arbitrary Command Execution2016-05-26

🕵️Threat Intelligence

2
Talos
Vulnerability Spotlight - LibBPG Image Decoding Code Execution2017-01-23
Talos
Vulnerability Spotlight - LibBPG Image Decoding Code Execution2017-01-23

💬Community

8
Bugzilla
CVE-2014-9911 icu: stack-based buffer overflow in uloc_getDisplayName2016-10-11
Bugzilla
CVE-2012-6703 kernel: Integer overflow in compress_core2016-06-29
Bugzilla
CVE-2014-9832 ImageMagick: heap overflow in pcx file2016-06-07
Bugzilla
CVE-2014-9830 ImageMagick: handling of corrupted sun file2016-06-07
Bugzilla
CVE-2014-9845 ImageMagick: crash due to corrupted dib file2016-06-07
CVE-2016-2014 (HIGH CVSS 8.1) | HPE Network Node Manager i (NNMi) 9 | cvebase.io