CVE-2019-18909

HIGH

HP ThinPro - OS Command Injection

Title source: llm
STIX 2.1

Description

The VPN software within HP ThinPro does not safely handle user supplied input, which may be leveraged by an attacker to inject commands that will execute with root privileges.

References (3)

Core 3
Core References
Vendor Advisory x_refsource_confirm
https://support.hp.com/us-en/document/c06509350
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2020/Mar/39

Scores

CVSS v3 8.0
EPSS 0.0018
EPSS Percentile 38.9%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (4)
hp/thinpro 6.2
hp/thinpro 6.2.1
hp/thinpro 7.0
hp/thinpro 7.1
Published Nov 22, 2019
Tracked Since Feb 18, 2026