← Vulnerability feed

Vulnerability record · CVE-2014-7874 · published 19 October 2014

CVE-2014-7874: Hp system management homepage cross-site request forgery vulnerability

Hp · System Management Homepage

Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) before 3.2.3 on HP-UX B.11.23, and before 3.2.8 on HP-UX B.11.31, allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

6.8 CVSS 2.0 Medium EPSS 1.6% · top 25.6% CWE-352 · Cross-site request forgery
6.8CVSS 2.0 base score
1.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) before 3.2.3 on HP-UX B.11.23, and before 3.2.8 on HP-UX B.11.31, allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-7874 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2015-3113Adobe Flash Player heap buffer overflow allows remote code executionAdobe Flash Player contains a heap-based buffer overflow (CWE-122/CWE-787) reachable through unspecified vectors. It affects Flash Player before 13.0…KEVEPSS 100%analysed9.8CVE-2012-1823PHP-CGI query string option injection enables remote code executionPHP versions before 5.3.12 and 5.4.x before 5.4.2, when run as a CGI script (php-cgi), mishandle query strings that lack an equals sign, allowing com…KEVEPSS 100%analysed8.8CVE-2015-8651Adobe Flash Player Integer Overflow Allows Remote Code ExecutionAdobe Flash Player, AIR, AIR SDK and AIR SDK & Compiler contain an integer overflow (CWE-190) that allows attackers to execute arbitrary code via uns…KEVEPSS 68%analysed7.5CVE-2015-5477ISC BIND TKEY Query Assertion Failure Denial of ServiceISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 mishandle TKEY queries, triggering a REQUIRE assertion failure that terminates the named dae…KEVEPSS 92%analysed10.0CVE-2012-2012Hp system management homepage vulnerabilityHP System Management Homepage (SMH) before 7.1.1 does not have an off autocomplete attribute for unspecified form fields, which makes it easier for r…EPSS 5.4%10.0CVE-2012-0131Hp distributed computing environment vulnerabilityDistributed Computing Environment (DCE) 1.8 and 1.9 on HP HP-UX B.11.11 and B.11.23 allows remote attackers to cause a denial of service or possibly …EPSS 7.4%10.0CVE-2011-1541Hp system management homepage vulnerabilityUnspecified vulnerability in HP System Management Homepage (SMH) before 6.3 allows remote attackers to bypass intended access restrictions, and conse…EPSS 12%10.0CVE-2008-1668Hp-ux permissions and access controls vulnerabilityftpd.c in (1) wu-ftpd 2.4.2 and (2) ftpd in HP HP-UX B.11.11 assigns uid 0 to the FTP client in certain operating-system misconfigurations in which P…EPSS 4.5%

Source: NIST National Vulnerability Database (record CVE-2014-7874), CISA KEV, FIRST EPSS (scores of 2026-10-09). This page is refreshed as NVD updates the record.