• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Hpe Warns Of A Critical Zero Day Flaw In Server Management

HPE warns of a critical zero-day flaw in server management software

You are here: Home / General Cyber Security News / HPE warns of a critical zero-day flaw in server management software
December 18, 2020

HPE has announced a critical zero-day vulnerability in a crucial server administration application that renders its Windows and Linux servers vulnerable to attack.

Trend Micro learned the vulnerability, which has the ID CVE-2020-7200 in the MITRE vulnerability databases. The vulnerability lies in HP’s Methods Perception Supervisor (SIM), an software that permits directors to examine a server’s wellbeing.

The bug has a foundation rating of 9.8 in the CVSS v3 vulnerability scoring program, which actions a security flaw’s severity on a scale of 1 to 10, putting it in the critical group. An attacker could exploit the difficulty to execute remote code on a Windows or Linux server, in accordance to HPE’s security advisory issued this 7 days.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


As a zero-working day bug, there’s no patch for this vulnerability, and HPE has not reported when just one will be out there. Instead, HPE claims it in “a foreseeable future release.” In the meantime, HPE has issued a workaround for Windows systems.

Administrators should halt the HPE SIM service and delete a file named “simsearch.war” from the Java-based mostly technique. This eliminates the federated research ability that contains the flaw, building it unusable.

SIM manages components across an array of HPE servers, including its ProLiant and Integrity units, along with storage and networking products and solutions. The system discovers units in the host infrastructure and presents inventory administration and reporting for them. It lets administrators monitor health and fitness with out applying software program brokers and configure guidelines to execute scripts and notify folks of failures.

HP launched the federated research attribute in 2011, allowing administrators to research the SIM Central Administration Server (CMS) for factors like static stock details and installed computer software. Devoid of this assistance, HP paperwork demonstrate that providers with many CMS methods will have a fragmented look at of company-broad inventory. 

“When large enterprises have CMSes unfold throughout various geographic locations, this limitation gets even additional acute,” HP’s merchandise paperwork say.

This workaround only is effective for Windows servers. There does not surface to be an fast plan for Linux server consumers.


Some sections of this article are sourced from:
www.itpro.co.uk

Previous Post: «Cyber Security News Will the US Move to a Federal Privacy Law in 2021?
Next Post: As Microsoft confirms breach, President Brad Smith argues for federal policy changes As Microsoft Confirms Breach, President Brad Smith Argues For Federal»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.