CVE-2023-4499

A potential security vulnerability has been identified in the HP ThinUpdate utility (also known as HP Recovery Image and Software Download Tool) which may lead to information disclosure. HP is releasing mitigation for the potential vulnerability.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:hp:thinupdate:*:*:*:*:*:*:*:*
OR cpe:2.3:h:hp:elite_mt645:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt21:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt22:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt31:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt32:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt43:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt44:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt45:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt46:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:pro_mt440_g3:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t430:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t530:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t540:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t628:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t630:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t638:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t640:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t730:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t740:-:*:*:*:*:*:*:*

History

19 Oct 2023, 20:18

Type Values Removed Values Added
References (MISC) https://support.hp.com/us-en/document/ish_9440593-9440618-16 - (MISC) https://support.hp.com/us-en/document/ish_9440593-9440618-16 - Patch, Vendor Advisory
CWE CWE-295
CPE cpe:2.3:h:hp:t630:-:*:*:*:*:*:*:*
cpe:2.3:a:hp:thinupdate:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:t628:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:elite_mt645:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt45:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t430:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt46:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt32:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t540:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt21:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t640:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t740:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:pro_mt440_g3:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t638:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt44:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt22:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t530:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t730:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt43:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt31:-:*:*:*:*:*:*:*
First Time Hp t730
Hp t628
Hp t430
Hp mt44
Hp
Hp t530
Hp mt32
Hp pro Mt440 G3
Hp thinupdate
Hp mt21
Hp elite Mt645
Hp t640
Hp t638
Hp mt22
Hp mt43
Hp t740
Hp mt31
Hp t630
Hp mt45
Hp mt46
Hp t540
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

13 Oct 2023, 21:31

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-13 17:15

Updated : 2023-10-19 20:18


NVD link : CVE-2023-4499

Mitre link : CVE-2023-4499


JSON object : View

Products Affected

hp

  • mt21
  • mt46
  • elite_mt645
  • mt22
  • mt43
  • t530
  • t640
  • t740
  • mt45
  • t730
  • t540
  • t638
  • thinupdate
  • t630
  • mt44
  • t628
  • mt32
  • mt31
  • t430
  • pro_mt440_g3
CWE
CWE-295

Improper Certificate Validation