CVE-2023-4499

A potential security vulnerability has been identified in the HP ThinUpdate utility (also known as HP Recovery Image and Software Download Tool) which may lead to information disclosure. HP is releasing mitigation for the potential vulnerability.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:hp:thinupdate:*:*:*:*:*:*:*:*
OR cpe:2.3:h:hp:elite_mt645:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt21:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt22:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt31:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt32:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt43:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt44:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt45:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt46:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:pro_mt440_g3:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t430:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t530:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t540:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t628:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t630:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t638:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t640:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t730:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t740:-:*:*:*:*:*:*:*

History

21 Nov 2024, 08:35

Type Values Removed Values Added
References () https://support.hp.com/us-en/document/ish_9440593-9440618-16 - Patch, Vendor Advisory () https://support.hp.com/us-en/document/ish_9440593-9440618-16 - Patch, Vendor Advisory

19 Oct 2023, 20:18

Type Values Removed Values Added
CPE cpe:2.3:h:hp:t630:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t640:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t740:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t430:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t730:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt32:-:*:*:*:*:*:*:*
cpe:2.3:a:hp:thinupdate:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:elite_mt645:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt45:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:pro_mt440_g3:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt31:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt21:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt22:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt44:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt43:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t540:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t530:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt46:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t638:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t628:-:*:*:*:*:*:*:*
CWE CWE-295
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
References (MISC) https://support.hp.com/us-en/document/ish_9440593-9440618-16 - (MISC) https://support.hp.com/us-en/document/ish_9440593-9440618-16 - Patch, Vendor Advisory
First Time Hp mt22
Hp mt46
Hp t740
Hp mt44
Hp mt43
Hp t628
Hp mt21
Hp mt45
Hp thinupdate
Hp t640
Hp
Hp t630
Hp t540
Hp mt32
Hp t638
Hp t530
Hp mt31
Hp t730
Hp t430
Hp pro Mt440 G3
Hp elite Mt645

13 Oct 2023, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-13 17:15

Updated : 2024-11-21 08:35


NVD link : CVE-2023-4499

Mitre link : CVE-2023-4499

CVE.ORG link : CVE-2023-4499


JSON object : View

Products Affected

hp

  • t730
  • t430
  • mt22
  • pro_mt440_g3
  • mt21
  • mt32
  • t638
  • mt43
  • t628
  • t640
  • mt44
  • mt46
  • mt45
  • t740
  • t540
  • mt31
  • elite_mt645
  • thinupdate
  • t630
  • t530
CWE
CWE-295

Improper Certificate Validation