{"cve":"CVE-2026-62545","enrichment":{"affected":[{"configurations":[{"platform":null,"status":"affected","versions":{"scheme":"generic","value":"11.2.25.0.000"}}],"enrichment":{"confidence":95.0,"confidence_source":"inferred","scores":[{"score":95.0,"source":"inferred"},{"score":100.0,"source":"matching"}]},"original":{"product":"Oracle Hyperion Infrastructure Technology","source":"cna","vendor":"Oracle Corporation"},"product":"hyperion_infrastructure_technology","vendor":"oracle"}],"created":"2026-08-19T01:15:12.516674+00:00","title":"Local Physical Access Exploit Enables Full Control of Oracle Hyperion Infrastructure Technology","updated":"2026-08-26T05:00:12.024827+00:00","vendors":["oracle","oracle$PRODUCT$hyperion_infrastructure_technology"],"weaknesses":["CWE-284"]},"epss":{"score":0.00331},"mitre":{"cpes":["cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*"],"created":"2026-08-18T21:00:28.002000+00:00","description":"Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration).   The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":7.5,"vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{}},"mitre_repo_path":"cves/2026/62xxx/CVE-2026-62545.json","references":["https://www.oracle.com/security-alerts/cspuaug2026.html"],"title":null,"updated":"2026-08-26T15:26:19.403000+00:00","vendors":["oracle","oracle$PRODUCT$hyperion_infrastructure_technology"],"weaknesses":[]},"nvd":{"cpes":["cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*"],"created":"2026-08-18T21:17:07.067000+00:00","description":"Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration).   The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":7.5,"vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{}},"nvd_repo_path":"2026/CVE-2026-62545.json","references":["https://www.oracle.com/security-alerts/cspuaug2026.html"],"title":null,"updated":"2026-08-26T16:16:33.037000+00:00","vendors":["oracle","oracle$PRODUCT$hyperion_infrastructure_technology"],"weaknesses":["CWE-284","NVD-CWE-noinfo"]},"opencve":{"changes":[{"created":"2026-08-18T21:15:00+00:00","data":[{"details":{"new":"Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration).   The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).","old":null},"type":"description"},{"details":["oracle","oracle$PRODUCT$hyperion_infrastructure_technology"],"type":"first_time"},{"details":{"added":["cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*"],"removed":[]},"type":"cpes"},{"details":{"added":["oracle","oracle$PRODUCT$hyperion_infrastructure_technology"],"removed":[]},"type":"vendors"},{"details":{"added":["https://www.oracle.com/security-alerts/cspuaug2026.html"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV3_1":{"score":7.5,"vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"e3cb3aec-5551-43a2-a79b-270eecbfb21e"},{"created":"2026-08-19T01:30:00+00:00","data":[{"details":{"new":"Unrestricted Physical Segment Access Enables Enterprise Takeover in Oracle Hyperion Infrastructure Technology","old":null},"type":"title"},{"details":{"added":["CWE-284"],"removed":[]},"type":"weaknesses"}],"id":"e81d9987-da82-4d71-803e-73fa8355c0a8"},{"created":"2026-08-21T10:00:00+00:00","data":[{"details":{"new":null,"old":"Unrestricted Physical Segment Access Enables Enterprise Takeover in Oracle Hyperion Infrastructure Technology"},"type":"title"},{"details":{"added":[],"removed":["CWE-284"]},"type":"weaknesses"}],"id":"3c8a491a-7c60-4190-b0a4-b088ca078475"},{"created":"2026-08-21T12:45:00+00:00","data":[{"details":{"new":"Hyperion Infrastructure Physical Access Vulnerability Allows Full System Takeover","old":null},"type":"title"},{"details":{"added":["CWE-284"],"removed":[]},"type":"weaknesses"}],"id":"dc3a2d8b-f906-4d76-8df4-bbeff80c6d69"},{"created":"2026-08-25T16:30:00+00:00","data":[{"details":{"added":["NVD-CWE-noinfo"],"removed":[]},"type":"weaknesses"}],"id":"ca3db77b-8496-4302-ab9b-f5bbcd5cc834"},{"created":"2026-08-25T20:30:00+00:00","data":[{"details":{"new":null,"old":"Hyperion Infrastructure Physical Access Vulnerability Allows Full System Takeover"},"type":"title"},{"details":{"added":[],"removed":["CWE-284"]},"type":"weaknesses"}],"id":"3bcc05f5-da48-47a4-8a4d-f2cfadc79d99"},{"created":"2026-08-26T05:15:00+00:00","data":[{"details":{"new":"Local Physical Access Exploit Enables Full Control of Oracle Hyperion Infrastructure Technology","old":null},"type":"title"},{"details":{"added":["CWE-284"],"removed":[]},"type":"weaknesses"}],"id":"9ff71f1f-28e8-40c9-8b75-ddddcc7c8c5a"},{"created":"2026-08-26T18:30:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"10a776e7-6da3-401b-bf07-6104ced8b90a"}],"cpes":{"data":["cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*"],"providers":["mitre","nvd"]},"created":{"data":"2026-08-18T21:00:28.002000+00:00","provider":"mitre"},"description":{"data":"Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration).   The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":7.5,"vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},"provider":"mitre"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.00331},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://www.oracle.com/security-alerts/cspuaug2026.html"],"providers":["mitre","nvd"]},"title":{"data":"Local Physical Access Exploit Enables Full Control of Oracle Hyperion Infrastructure Technology","provider":"enrichment"},"updated":{"data":"2026-08-26T16:16:33.037000+00:00","provider":"nvd"},"vendors":{"data":["oracle","oracle$PRODUCT$hyperion_infrastructure_technology"],"providers":["mitre","nvd","enrichment"]},"weaknesses":{"data":["CWE-284","NVD-CWE-noinfo"],"providers":["nvd","vulnrichment","enrichment"]}},"vulnrichment":{"cpes":[],"created":"2026-08-18T21:00:28.002000+00:00","description":"Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration).   The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"references":[],"title":null,"updated":"2026-08-26T13:48:54.996000+00:00","vendors":[],"vulnrichment_repo_path":"2026/62xxx/CVE-2026-62545.json","weaknesses":["CWE-284"]}}