CVE-2020-7136 is a critical security vulnerability in HPE Smart Update Manager (SUM) versions prior to 8.5.6, allowing remote unauthorized access. With a CVSS score of 9.8, it presents a severe risk, enabling unauthenticated attackers to compromise confidentiality, integrity, and availability. While not listed in CISA KEV, exploit code is available via Nuclei templates, and its high EPSS score and community discussion indicate a significant likelihood of exploitation. HPE has released updates to address this flaw, urging users to upgrade to SUM 8.5.6 or later.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.5.6CPE matchmatch criteria | cpe:2.3:a:hpe:smart_update_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HPE Smart Update Manager 8.4.5 Remote Unauthorized Access
Jan 15, 2020HPE Smart Update Manager 8.4.5 Remote Unauthorized Access
Jan 15, 2020HPE Smart Update Manager 8.4.5 Remote Unauthorized Access
Jan 15, 2020HPE Smart Update Manager 8.4.5 Remote Unauthorized Access
Jan 15, 2020HPE Smart Update Manager 8.4.5 Remote Unauthorized Access
Jan 15, 2020