Impact
A local attacker can potentially raise their privileges on a system running HP ImageDiags versions before 5.0.0.36. The flaw stems from insufficient access controls that fail to restrict privileged actions to authorized users, allowing an attacker with local access to exploit the software and gain elevated rights. This weakness can lead to unauthorized system changes, data theft, or further lateral movement within the organization. It is classified as a CWE-379 vulnerability.
Affected Systems
HP ImageDiags from HP Inc. is affected. All releases earlier than version 5.0.0.36 lack the fix. Users should confirm that their environment runs at least 5.0.0.36 or a later updated release.
Risk and Exploitability
The CVSS score of 7 indicates a high impact and medium likelihood of exploitation. The EPSS score is not available, so the exact probability is uncertain, but the absence of a KEV listing suggests that no widespread attacks have been observed yet. The attack vector is local, meaning an attacker must already have some form of access or presence on the target machine. Under those conditions, the flaw can be leveraged to gain privileged system access.
OpenCVE Enrichment