CVE-2019-16287

MEDIUM

HP ThinPro Linux <7.1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

In HP ThinPro Linux 6.2, 6.2.1, 7.0 and 7.1, an attacker may be able to leverage the application filter bypass vulnerability to gain privileged access to create a file on the local file system whose presence puts the device in Administrative Mode, which will allow the attacker to executed commands with elevated privileges.

References (3)

Core 3
Core References
Vendor Advisory x_refsource_confirm
https://support.hp.com/us-en/document/c06509350
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2020/Mar/38

Scores

CVSS v3 6.8
EPSS 0.0016
EPSS Percentile 36.8%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (4)
hp/thinpro 6.2
hp/thinpro 6.2.1
hp/thinpro 7.0
hp/thinpro 7.1
Published Nov 22, 2019
Tracked Since Feb 18, 2026