CVE-2023-4499

A potential security vulnerability has been identified in the HP ThinUpdate utility (also known as HP Recovery Image and Software Download Tool) which may lead to information disclosure. HP is releasing mitigation for the potential vulnerability.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:hp:thinupdate:*:*:*:*:*:*:*:*
OR cpe:2.3:h:hp:elite_mt645:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt21:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt22:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt31:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt32:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt43:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt44:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt45:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt46:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:pro_mt440_g3:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t430:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t530:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t540:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t628:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t630:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t638:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t640:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t730:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t740:-:*:*:*:*:*:*:*

History

21 Nov 2024, 08:35

Type Values Removed Values Added
References () https://support.hp.com/us-en/document/ish_9440593-9440618-16 - Patch, Vendor Advisory () https://support.hp.com/us-en/document/ish_9440593-9440618-16 - Patch, Vendor Advisory

19 Oct 2023, 20:18

Type Values Removed Values Added
References (MISC) https://support.hp.com/us-en/document/ish_9440593-9440618-16 - (MISC) https://support.hp.com/us-en/document/ish_9440593-9440618-16 - Patch, Vendor Advisory
CPE cpe:2.3:h:hp:t740:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt22:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t540:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt21:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t430:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t630:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t638:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:elite_mt645:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:pro_mt440_g3:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt32:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt44:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt43:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t628:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt31:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt46:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t730:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt45:-:*:*:*:*:*:*:*
cpe:2.3:a:hp:thinupdate:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:t640:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t530:-:*:*:*:*:*:*:*
CWE CWE-295
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Hp mt31
Hp thinupdate
Hp mt43
Hp t530
Hp
Hp mt46
Hp elite Mt645
Hp t540
Hp mt21
Hp t638
Hp t628
Hp mt45
Hp pro Mt440 G3
Hp mt22
Hp t730
Hp mt32
Hp mt44
Hp t430
Hp t630
Hp t640
Hp t740

13 Oct 2023, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-13 17:15

Updated : 2024-11-21 08:35


NVD link : CVE-2023-4499

Mitre link : CVE-2023-4499

CVE.ORG link : CVE-2023-4499


JSON object : View

Products Affected

hp

  • mt22
  • t730
  • t628
  • t530
  • mt44
  • t630
  • t638
  • elite_mt645
  • mt32
  • thinupdate
  • pro_mt440_g3
  • t740
  • mt21
  • t540
  • t430
  • mt31
  • mt45
  • mt46
  • mt43
  • t640
CWE
CWE-295

Improper Certificate Validation