CVE-2007-6513 EXPLOIT
4.3
MEDIUM · CVSS 2.0 · EPSS 2.3% (pctl 83)
Patch early
A public exploit exists.
Description
HP eSupportDiagnostics ActiveX control (hpediag.dll) 1.0.11.0 exports dangerous methods, which allows remote attackers to (1) read arbitrary files via the ReadTextFile method, or (2) read arbitrary registry values via the ReadValue method.
Scoring
| CVSS | 4.3 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
| EPSS | 2.32% — more likely to be exploited than 83% of all CVEs |
| Weakness | CWE-200 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-12-21 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| hp | esupportdiagnostics |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | HP eSupportDiagnostics 1.0.11 - 'hpediag.dll' ActiveX Control Multiple Information Disclosure Vulnerabilities | 2007-12-20 |
References
- http://archives.neohapsis.com/archives/fulldisclosure/2007-12/0470.html
- http://www.heise-security.co.uk/news/100934
- http://www.securityfocus.com/bid/26967
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39156
- http://archives.neohapsis.com/archives/fulldisclosure/2007-12/0470.html
- http://www.heise-security.co.uk/news/100934
- http://www.securityfocus.com/bid/26967
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39156
→ the Explorer · watch your stack · NVD