Back

CVE-2020-7136

CRITICAL

A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access. Hewlett Packard Enterprise has provided a software update to resolve this vulnerability in HPE Smart Update Manager (SUM) prior to 8.5.6. Please visit the HPE Support Center at https://support.hpe.com/hpesc/public/home to download the latest version of HPE Smart Update Manager (SUM). Download the latest version of HPE Smart Update Manager (SUM) or download the latest Service Pack For ProLiant (SPP).

Published: Apr 30, 2020 Modified: Jun 17, 2026
NVD-CWE-noinfo

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
hpe smart_update_manager * < 8.5.6

GitHub Security Advisory GHSA-jp2q-w73p-9cf9

A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 79.52%

Top 0% most likely to be exploited

Threat Score 73.1 / 100

Data Sources

NVD EPSS GitHub