本頁列出影響 hp thinpro 的已公開 CVE 漏洞(透過 NVD CPE 關聯)。每列包含嚴重程度評分、摘要與發布日期,便於識別與分析安全議題。
| CVE | 摘要 | 來源 | 最高 CVSS | EPSS % | 公開時間 | 更新時間 |
|---|---|---|---|---|---|---|
| CVE-2025-43017 | HP ThinPro 8.1 System management application failed to verify user's true id. HP has released HP ThinPro 8.1 SP8, which includes updates to mitigate potential vulnerabilities. | [email protected] | 8.5 | 0.22% | 2025-10-28 | 2026-06-17 |
| CVE-2025-43024 | A GUI dialog of an application allows to view what files are in the file system without proper authorization. | [email protected] | 5.1 | 0.25% | 2025-10-27 | 2026-06-17 |
| CVE-2022-1602 | A potential security vulnerability has been identified in HP ThinPro 7.2 Service Pack 8 (SP8). The security vulnerability in SP8 is not remedied after upgrading from SP8 to Service Pack 9 (SP9). HP has released Service Pack 10 (SP10) to remediate the potential vulnerability introduced in SP8. | [email protected] | 5.5 | 0.18% | 2022-09-13 | 2026-06-17 |
| CVE-2019-18910 | The Citrix Receiver wrapper function does not safely handle user supplied input, which may be leveraged by an attacker to inject commands that will execute with local user privileges. | [email protected] | 6.8 | 0.85% | 2019-11-22 | 2026-06-16 |
| CVE-2019-18909 | The VPN software within HP ThinPro does not safely handle user supplied input, which may be leveraged by an attacker to inject commands that will execute with root privileges. | [email protected] | 8.0 | 2.18% | 2019-11-22 | 2026-06-16 |
| CVE-2019-16287 | In HP ThinPro Linux 6.2, 6.2.1, 7.0 and 7.1, an attacker may be able to leverage the application filter bypass vulnerability to gain privileged access to create a file on the local file system whose presence puts the device in Administrative Mode, which will allow the attacker to executed commands with elevated privileges. | [email protected] | 6.8 | 0.68% | 2019-11-22 | 2026-06-16 |
| CVE-2017-2740 | A potential security vulnerability has been identified with the command line shell of the HP ThinPro operating system 6.1, 5.2.1, 5.2, 5.1, 5.0, and 4.4. The vulnerability could result in a local unauthorized elevation of privilege on an HP thin client device. | [email protected] | 7.8 | 0.52% | 2018-01-23 | 2026-06-16 |
| CVE-2016-2246 | HP ThinPro 4.4 through 6.1 mishandles the keyboard layout control panel and virtual keyboard application, which allows local users to bypass intended access restrictions and gain privileges via unspecified vectors. | [email protected] | 7.8 | 0.57% | 2016-12-29 | 2026-06-16 |