← Vulnerability feed

Vulnerability record · CVE-2017-8978 · published 15 February 2018

CVE-2017-8978: Hp icewall mcrp information exposure vulnerability

Hp · Icewall Mcrp

A Remote Unauthorized Disclosure of Information vulnerability in HPE IceWall Products version MFA 4.0 proxy was found.

4.6 CVSS 3.0 Medium EPSS 0.56% · top 55.2% CWE-200 · Information exposure
4.6CVSS 3.0 base score, v2 4.9
0.56%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A Remote Unauthorized Disclosure of Information vulnerability in HPE IceWall Products version MFA 4.0 proxy was found.

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-8978 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-2182Hp icewall federation agent out-of-bounds write vulnerabilityThe BN_bn2dec function in crypto/bn/bn_print.c in OpenSSL before 1.1.0 does not properly validate division results, which allows remote attackers to …EPSS 46%9.8CVE-2016-2177Hp icewall mcrp integer overflow vulnerabilityOpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a denial of s…EPSS 45%9.1CVE-2017-8989Hp icewall sso open redirect vulnerabilityA security vulnerability in HPE IceWall SSO Dfw 10.0 and 11.0 on RHEL, HP-UX, and Windows could be exploited remotely to allow URL Redirection.EPSS 1.8%5.9CVE-2016-6306Openssl out-of-bounds read vulnerabilityThe certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read…EPSS 42%5.0CVE-2014-2604Hp icewall mcrp vulnerabilityUnspecified vulnerability in HP IceWall SSO 10.0 Dfw and IceWall MCRP 2.1 and 3.0 allows remote attackers to cause a denial of service via unknown ve…EPSS 3.5%4.3CVE-2015-3196Hp icewall sso race condition vulnerabilityssl/s3_clnt.c in OpenSSL 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and 1.0.2 before 1.0.2d, when used for a multi-threaded client, writes the PSK ide…EPSS 14%5.9CVE-2025-68686FortiOS symbolic link patch bypass exposes sensitive informationFortiOS contains an information exposure flaw (CWE-200) that lets a remote unauthenticated attacker bypass the patch for the symbolic link persistenc…KEVEPSS 29%analysed7.5CVE-2026-20133Cisco Catalyst SD-WAN Manager insufficient file system restrictions expose dataCisco Catalyst SD-WAN Software has insufficient file system restrictions that let an attacker read sensitive files on the underlying operating system…KEVEPSS 32%analysed

Source: NIST National Vulnerability Database (record CVE-2017-8978), CISA KEV, FIRST EPSS (scores of 2026-10-08). This page is refreshed as NVD updates the record.