CVE-2020-7136
HPE Smart Update Manager (SUM) Remote Unauthorized Access Vulnerability
Record summary
CVE-2020-7136 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access. Hewlett Packard Enterprise has provided a software update to resolve this vulnerability in HPE Smart Update Manager (SUM) prior to 8.5.6. Please visit the HPE Support Center at https://support.hpe.com/hpesc/public/home to download the latest version of HPE Smart Update Manager (SUM). Download the latest version of HPE Smart Update Manager (SUM) or download the latest Service Pack For ProLiant (SPP).
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Aug 14, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Smart Update Manager (SUM)Browse Hewlett Packard Enterprise / Smart Update Manager (SUM) | CVE List | Prior to v8.5.6 | affected |
smart_update_managerBrowse hpe / smart_update_manager | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALHPE Smart Update Manager < 8.5.6 - Remote Unauthorized AccessCVSS 9.8
HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access.
Impact
An attacker can gain unauthorized access to the HPE Smart Update Manager, potentially leading to further compromise of the system.
Remediation
Hewlett Packard Enterprise has provided a software update to resolve this vulnerability in HPE Smart Update Manager (SUM) prior to 8.5.6. Please visit the HPE Support Center at https://support.hpe.com/hpesc/public/home to download the latest version of HPE Smart Update Manager (SUM). Download the latest version of HPE Smart Update Manager (SUM) or download the latest Service Pack For ProLiant (SPP).
Source: ProjectDiscovery