CVE-2012-2012: HP System Management Homepage
High severity, CVSS 10.0. EPSS: 5.4% chance of exploitation in the next 30 days.
HP System Management Homepage (SMH) before 7.1.1 does not have an off autocomplete attribute for unspecified form fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.
Affected products
- HP System Management Homepage: up to and including 7.1.0-16; version 2.0.0 only; version 2.0.1 only; version 2.0.1.104 only; version 2.0.2 only; version 2.0.2.106 only; …
Published 2012-06-29. Last modified 2026-06-16.