CVE-2025-43017 Details
Description
HP ThinPro 8.1 System management application failed to verify user's true id. HP has released HP ThinPro 8.1 SP8, which includes updates to mitigate potential vulnerabilities.
A vulnerability in the HP ThinPro 8.1 system management application exists due to improper verification of user identities. This flaw could potentially be exploited to escalate privileges, execute arbitrary code, cause a denial of service, or lead to unauthorized information disclosure. HP has addressed this vulnerability in the recently released HP ThinPro 8.1 SP8.
Users can upgrade to HP ThinPro 8.1 SP8 to address this vulnerability. Instructions for downloading this update are available on the HP Customer Support - Software and Driver Downloads site.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 30, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.hp.com/us-en/document/ish_13164593-13164617-16/hpsbhf04066 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-250 | Execution with Unnecessary Privileges | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| hp thinpro | 8.1 sp2 8.1 sp3 8.1 sp4 8.1 sp5 8.1 sp6 8.1 sp7 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 21, 2026 | Initial Analysis | [email protected] |
| Oct 28, 2025 | New CVE Received | [email protected] |