CVE-2024-51770

7.5

Hewlett Packard Enterprise · AutoPass License Server (APLS)

A vulnerability in HPE AutoPass License Server allows for unauthenticated information disclosure due to a lack of proper access controls.

Executive summary

An information disclosure vulnerability in HPE AutoPass License Server allows unauthenticated remote attackers to access sensitive data, posing a significant risk to license management integrity.

Vulnerability

This vulnerability is an information disclosure flaw that can be triggered by an unauthenticated attacker over the network. The vulnerability exists because the application fails to adequately restrict access to sensitive information, allowing an external party to retrieve data without credentials.

Business impact

The exploitation of this vulnerability could lead to the unauthorized exposure of sensitive configuration or licensing data, which may facilitate further attacks on the infrastructure. With a CVSS score of 7.5, the risk is considered High, as the flaw is remotely exploitable and does not require user interaction or prior authentication. Organizations should treat this as a priority to prevent potential intelligence gathering by malicious actors.

Remediation

Immediate Action: Upgrade Hewlett Packard Enterprise AutoPass License Server to version 9.17 or later as specified in the official vendor advisory.

Proactive Monitoring: Review web server and application access logs for unusual patterns of requests, specifically those targeting configuration endpoints or license-related files.

Compensating Controls: Implement network-level access controls or a Web Application Firewall (WAF) to restrict access to the AutoPass License Server interface to trusted IP addresses only.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the ease of exploitability and the potential for unauthorized data exposure, administrators must prioritize the update of all instances of HPE AutoPass License Server to version 9.17. While no active exploitation is currently confirmed, the nature of the flaw makes it an attractive target for automated discovery, necessitating immediate patching to secure the environment.

More Hewlett Packard Enterprise CVEs

Sources