CVE-2023-26295
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Jun 12, 2023
Updated: Jan 6, 2025
CWE ID 77
Summary
CVE-2023-26295 is a vulnerability affecting previous versions of HP Device Manager. This issue could permit an attacker to inject commands or elevate privileges, potentially leading to serious security consequences. HP Device Manager, a tool used for managing HP devices, contains a vulnerability that may allow unauthorized users to gain elevated access. Prior to version 5.0.10, this software was susceptible to command injection and privilege escalation attacks. Users are urged to update to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- HP Device Manager
Affected Vendors
- HP