CVE-2024-28893

C

ertain HP software packages (SoftPaqs) are potentially vulnerable to arbitrary code execution when the SoftPaq configuration file has been modified after extraction. HP has released updated software packages (SoftPaqs).

Configurations

Configuration 1 (hide)

cpe:2.3:a:hp:softpaqs:-:*:*:*:*:*:*:*

History

14 Jan 2026, 16:54

Type Values Removed Values Added
References () https://support.hp.com/us-en/document/ish_10502451-10502508-16/hpsbhf03931 - () https://support.hp.com/us-en/document/ish_10502451-10502508-16/hpsbhf03931 - Vendor Advisory
First Time Hp softpaqs
Hp
CPE cpe:2.3:a:hp:softpaqs:-:*:*:*:*:*:*:*

27 Mar 2025, 15:15

Type Values Removed Values Added
CWE CWE-94

21 Nov 2024, 09:07

Type Values Removed Values Added
References () https://support.hp.com/us-en/document/ish_10502451-10502508-16/hpsbhf03931 - () https://support.hp.com/us-en/document/ish_10502451-10502508-16/hpsbhf03931 -

03 Jul 2024, 01:51

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.7

01 May 2024, 19:50

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-01 16:15

Updated : 2026-01-14 16:54


NVD link : CVE-2024-28893

Mitre link : CVE-2024-28893

CVE.ORG link : CVE-2024-28893


JSON object : View

Products Affected
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')