Back
CVE-2020-7136
CRITICAL
A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access. Hewlett Packard Enterprise has provided a software update to resolve this vulnerability in HPE Smart Update Manager (SUM) prior to 8.5.6. Please visit the HPE Support Center at https://support.hpe.com/hpesc/public/home to download the latest version of HPE Smart Update Manager (SUM). Download the latest version of HPE Smart Update Manager (SUM) or download the latest Service Pack For ProLiant (SPP).
Published: Apr 30, 2020
Modified: Jun 17, 2026
NVD-CWE-noinfo
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| hpe | smart_update_manager | * < 8.5.6 |
GitHub Security Advisory GHSA-jp2q-w73p-9cf9
A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow...
References (2)
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
79.52%
Top 0% most likely to be exploited
Threat Score
73.1 / 100
Data Sources
NVD
EPSS
GitHub