← Vulnerability feed

Vulnerability record · CVE-2020-7136 · published 30 April 2020

CVE-2020-7136: HPE Smart Update Manager remote unauthorized access flaw

Hpe · Smart Update Manager

HPE Smart Update Manager (SUM) before version 8.5.6 contains a flaw that could allow remote unauthorized access. The vendor description is thin and does not name the root cause, but the critical CVSS score and network vector indicate a serious exposure for anyone running an unpatched SUM instance.

9.8 CVSS 3.1 Critical EPSS 80% · top 0.4%
9.8CVSS 3.1 base score, v2 10.0
80%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access. Hewlett Packard Enterprise has provided a software update to resolve this vulnerability in HPE Smart Update Manager (SUM) prior to 8.5.6. Please visit the HPE Support Center at https://support.hpe.com/hpesc/public/home to download the latest version of HPE Smart Update Manager (SUM). Download the latest version of HPE Smart Update Manager (SUM) or download the latest Service Pack For ProLiant (SPP).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with a network, unauthenticated, no-interaction vector and very high EPSS make this an urgent patch target despite the thin description.

What it is

HPE Smart Update Manager (SUM) before version 8.5.6 contains a flaw that could allow remote unauthorized access. The vendor description is thin and does not name the root cause, but the critical CVSS score and network vector indicate a serious exposure for anyone running an unpatched SUM instance.

Impact

An unauthenticated remote attacker could gain unauthorized access to the affected SUM deployment, with the CVSS vector indicating high impact to confidentiality, integrity and availability.

Attack surface

The flaw is reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The record does not specify which SUM interface or service is exposed.

Exploitation

Not listed in CISA KEV and no public exploit references are tagged, but EPSS is very high at roughly 0.795 (99.6th percentile), suggesting elevated real-world exploitation likelihood.

What to do

  • Upgrade HPE Smart Update Manager to version 8.5.6 or later, or apply the latest Service Pack for ProLiant (SPP) as directed by the vendor advisory.
  • If SUM cannot be patched immediately, restrict network access to its management interfaces to trusted hosts only.
  • Do not expose SUM management ports to untrusted networks or the internet.
  • Verify the deployed SUM version against the vendor advisory and track completion of upgrades.
  • Monitor the HPE support advisory for any updated guidance.

Detection

  • Inventory hosts running HPE Smart Update Manager and flag any version below 8.5.6.
  • Monitor network logs for unexpected inbound connections to SUM management ports from untrusted sources.
  • Review SUM and host logs for anomalous administrative or update actions originating from remote addresses.
  • Alert on new or unusual processes spawned by SUM services on managed hosts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-7136 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2020-7136), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.