Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-7136

79
FAUCET Score

CVE-2020-7136 is a critical security vulnerability in HPE Smart Update Manager (SUM) versions prior to 8.5.6, allowing remote unauthorized access. With a CVSS score of 9.8, it presents a severe risk, enabling unauthenticated attackers to compromise confidentiality, integrity, and availability. While not listed in CISA KEV, exploit code is available via Nuclei templates, and its high EPSS score and community discussion indicate a significant likelihood of exploitation. HPE has released updates to address this flaw, urging users to upgrade to SUM 8.5.6 or later.

Impacted Technologies

VendorProductVersion(s)CPE
< 8.5.6CPE matchmatch criteria
cpe:2.3:a:hpe:smart_update_manager:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
79.52%
Probability of exploitation in next 30 days
EPSS Percentile
99.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
Nuclei: CVE-2020-7136 · Jan 11, 2022
This CVE's current EPSS score of 0.7952 is in the 98th percentile among its peer group of 36,829 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (5)

boschvendor investigatingvia llm_extracted
maxkbvendor investigatingvia llm_extracted
naturalintelligencevendor investigatingvia llm_extracted
netgearvendor investigatingvia llm_extracted
opnsensevendor investigatingvia llm_extracted

Vendor Advisories (5)

netgearllm-netgear-568fc22da37d8fe1CRITICAL

HPE Smart Update Manager 8.4.5 Remote Unauthorized Access

Jan 15, 2020
maxkbllm-maxkb-6d14dc91ccdc814dCRITICAL

HPE Smart Update Manager 8.4.5 Remote Unauthorized Access

Jan 15, 2020
boschllm-bosch-e7f0dc2e4dc18ce3CRITICAL

HPE Smart Update Manager 8.4.5 Remote Unauthorized Access

Jan 15, 2020
opnsensellm-opnsense-7421257c118bb917CRITICAL

HPE Smart Update Manager 8.4.5 Remote Unauthorized Access

Jan 15, 2020
naturalintelligencellm-naturalintelligence-1f69ae2a7888feffCRITICAL

HPE Smart Update Manager 8.4.5 Remote Unauthorized Access

Jan 15, 2020

References

support.hpe.com / hpsc/doc/public/display
Vendor Advisory