CVE-2019-11996
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Potential security vulnerabilities have been identified with HPE Nimble Storage systems in multi array group configurations. The vulnerabilities could be exploited by an attacker to gain elevated privileges on the array. The following NimbleOS versions, and all subsequent releases, contain a software fix for this vulnerability: 3.9.2.0, 4.5.5.0, 5.0.8.0 and 5.1.3.0.
Affected (4)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.1.0.0 to 3.9.1.0 |
| Running on/with | Platform Versions |
|---|---|
Hpe Nimble Storage Af20 All Flash Array | All versions |
Hpe Nimble Storage Af20q All Flash Dual Controller | All versions |
Hpe Nimble Storage Af40 All Flash Dual Controller | All versions |
Hpe Nimble Storage Af60 All Flash Dual Controller | All versions |
Hpe Nimble Storage Af80 All Flash Dual Controller | All versions |
Hpe Nimble Storage Cs3000 | All versions |
Hpe Nimble Storage Cs5000 | All versions |
Hpe Nimble Storage Cs7000 | All versions |
Hpe Nimble Storage Secondary Flash Arrays | All versions |
References (2)
Source: security-alert@hpe.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.