CVE-2023-4499

A potential security vulnerability has been identified in the HP ThinUpdate utility (also known as HP Recovery Image and Software Download Tool) which may lead to information disclosure. HP is releasing mitigation for the potential vulnerability.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:hp:thinupdate:*:*:*:*:*:*:*:*
OR cpe:2.3:h:hp:elite_mt645:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt21:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt22:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt31:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt32:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt43:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt44:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt45:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt46:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:pro_mt440_g3:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t430:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t530:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t540:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t628:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t630:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t638:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t640:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t730:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t740:-:*:*:*:*:*:*:*

History

19 Oct 2023, 20:18

Type Values Removed Values Added
CWE CWE-295
CPE cpe:2.3:h:hp:t540:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t530:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t628:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt32:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt46:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t630:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t740:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt43:-:*:*:*:*:*:*:*
cpe:2.3:a:hp:thinupdate:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:t638:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:pro_mt440_g3:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt22:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt44:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt31:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t640:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t730:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:elite_mt645:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt45:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:t430:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:mt21:-:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Hp mt44
Hp t628
Hp mt31
Hp thinupdate
Hp mt21
Hp mt22
Hp t430
Hp t540
Hp mt43
Hp t630
Hp mt46
Hp t740
Hp t638
Hp mt32
Hp pro Mt440 G3
Hp t640
Hp t730
Hp mt45
Hp t530
Hp elite Mt645
Hp
References (MISC) https://support.hp.com/us-en/document/ish_9440593-9440618-16 - (MISC) https://support.hp.com/us-en/document/ish_9440593-9440618-16 - Patch, Vendor Advisory

13 Oct 2023, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-13 17:15

Updated : 2023-12-10 15:14


NVD link : CVE-2023-4499

Mitre link : CVE-2023-4499

CVE.ORG link : CVE-2023-4499


JSON object : View

Products Affected

hp

  • t530
  • t730
  • t640
  • t638
  • elite_mt645
  • mt45
  • mt21
  • pro_mt440_g3
  • t630
  • mt43
  • t430
  • mt32
  • mt46
  • thinupdate
  • t740
  • mt22
  • mt31
  • mt44
  • t540
  • t628
CWE
CWE-295

Improper Certificate Validation