CVE-2020-7200 is a critical remote code execution vulnerability affecting HPE Systems Insight Manager (SIM) version 7.6. With a CVSS score of 9.8, it allows unauthenticated attackers to execute arbitrary code remotely with low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. While not listed in CISA KEV, exploit modules are publicly available (e.g., Metasploit), and it has garnered significant community discussion and media attention, indicating a high likelihood of exploitation. Its high EPSS and FAUCET Risk Score further underscore the urgency of patching this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.6CPE matchmatch criteria | cpe:2.3:a:hp:systems_insight_manager:7.6:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.