{"api_version":"1","generated_at":"2026-07-23T10:13:48+00:00","cve":"CVE-2007-6513","urls":{"html":"https://cve.report/CVE-2007-6513","api":"https://cve.report/api/cve/CVE-2007-6513.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-6513","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-6513"},"summary":{"title":"CVE-2007-6513","description":"HP eSupportDiagnostics ActiveX control (hpediag.dll) 1.0.11.0 exports dangerous methods, which allows remote attackers to (1) read arbitrary files via the ReadTextFile method, or (2) read arbitrary registry values via the ReadValue method.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-12-21 22:46:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-200","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/26967","name":"http://www.securityfocus.com/bid/26967","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"HP eSupportDiagnostics 'hpediag.dll' ActiveX Control Multiple Information Disclosure Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/39156","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/39156","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://archives.neohapsis.com/archives/fulldisclosure/2007-12/0470.html","name":"http://archives.neohapsis.com/archives/fulldisclosure/2007-12/0470.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.heise-security.co.uk/news/100934","name":"http://www.heise-security.co.uk/news/100934","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security leak in HP Software Update - heise Security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-6513","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-6513","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"6513","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hp","cpe5":"esupportdiagnostics","cpe6":"1.0.11.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T16:11:06.013Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20071219 HP eSupportDiagnostics hpediags.dll Information Disclosure","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://archives.neohapsis.com/archives/fulldisclosure/2007-12/0470.html"},{"name":"26967","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/26967"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.heise-security.co.uk/news/100934"},{"name":"hp-esupportdiagnostics-info-disclosure(39156)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/39156"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-12-19T00:00:00.000Z","descriptions":[{"lang":"en","value":"HP eSupportDiagnostics ActiveX control (hpediag.dll) 1.0.11.0 exports dangerous methods, which allows remote attackers to (1) read arbitrary files via the ReadTextFile method, or (2) read arbitrary registry values via the ReadValue method."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-07T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20071219 HP eSupportDiagnostics hpediags.dll Information Disclosure","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://archives.neohapsis.com/archives/fulldisclosure/2007-12/0470.html"},{"name":"26967","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/26967"},{"tags":["x_refsource_MISC"],"url":"http://www.heise-security.co.uk/news/100934"},{"name":"hp-esupportdiagnostics-info-disclosure(39156)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/39156"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-6513","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"HP eSupportDiagnostics ActiveX control (hpediag.dll) 1.0.11.0 exports dangerous methods, which allows remote attackers to (1) read arbitrary files via the ReadTextFile method, or (2) read arbitrary registry values via the ReadValue method."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20071219 HP eSupportDiagnostics hpediags.dll Information Disclosure","refsource":"FULLDISC","url":"http://archives.neohapsis.com/archives/fulldisclosure/2007-12/0470.html"},{"name":"26967","refsource":"BID","url":"http://www.securityfocus.com/bid/26967"},{"name":"http://www.heise-security.co.uk/news/100934","refsource":"MISC","url":"http://www.heise-security.co.uk/news/100934"},{"name":"hp-esupportdiagnostics-info-disclosure(39156)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/39156"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-6513","datePublished":"2007-12-21T22:00:00.000Z","dateReserved":"2007-12-21T00:00:00.000Z","dateUpdated":"2024-08-07T16:11:06.013Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-12-21 22:46:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-200","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:hp:esupportdiagnostics:1.0.11.0:*:*:*:*:*:*:*","matchCriteriaId":"3B02F63D-A3C4-413B-A2AE-5ADE81148CE7"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"6513","Ordinal":"1","Title":"CVE-2007-6513","CVE":"CVE-2007-6513","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"6513","Ordinal":"1","NoteData":"HP eSupportDiagnostics ActiveX control (hpediag.dll) 1.0.11.0 exports dangerous methods, which allows remote attackers to (1) read arbitrary files via the ReadTextFile method, or (2) read arbitrary registry values via the ReadValue method.","Type":"Description","Title":"CVE-2007-6513"},{"CveYear":"2007","CveId":"6513","Ordinal":"2","NoteData":"2007-12-21","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"6513","Ordinal":"3","NoteData":"2017-08-07","Type":"Other","Title":"Modified"}]}}}