CVE-2019-18909
CVE-2019-18909
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 2.2%KEV nãoPoC —Patch —
Lifecycle
22 Nov 2019Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The VPN software within HP ThinPro does not safely handle user supplied input, which may be leveraged by an attacker to inject commands that will execute with root privileges.
Affected products
HP · ThinPro LinuxWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →