A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access. Hewlett Packard Enterprise has provided a software update to resolve this vulnerability in HPE Smart Update Manager (SUM) prior to 8.5.6. Please visit the HPE Support Center at https://support.hpe.com/hpesc/public/home to download the latest version of HPE Smart Update Manager (SUM). Download the latest version of HPE Smart Update Manager (SUM) or download the latest Service Pack For ProLiant (SPP).
AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence82%
Public exploitation · VTP factUNKNOWN
Assessment
HPE Smart Update Manager before 8.5.6 contains a remotely reachable unauthorized-access vulnerability. The supplied CVSS is 9.8 with complete confidentiality, integrity, and availability impact, and HPE provides an update resolving the issue. EPSS is high at 0.79522, but no exploitation evidence is supplied.
Why it matters
Unauthenticated remote access to an update-management system could expose or alter sensitive management operations.
The high-impact vector and elevated EPSS make exposed unpatched instances important to track, without proving exploitation.
Evidence
1 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.
Uncertainties
The supplied description does not specify the affected interface or exact unauthorized capabilities.
Only one reference is counted, with no source text, KEV entry, assertions, or first-party telemetry supplied.
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
Next watchpoint
Inventory HPE Smart Update Manager versions earlier than 8.5.6 and assess network exposure.
AI baseline history (1)
BASELINE ASSESSED
HPE Smart Update Manager unauthorized accessgpt-5.6-sol · high
Evidence confidence0%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
EPSS is 0.80; this is predictive context, not exploitation evidence.
02
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
02
Material change ledger
What changed
No material changes are recorded for this subject.
03
Claim provenance
Evidence and source independence
0publications detected
0underlying evidence chains
0 primary sources · 0 dependent secondary reports · 0 reports with unresolved independence. Repetition remains visible without multiplying confirmation.
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.