← Back

CVE-2020-7138

nvd nist
Published: May 19, 2020Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Potential remote code execution security vulnerabilities have been identified with HPE Nimble Storage systems that could be exploited by an attacker to gain elevated privileges on the array. The following NimbleOS versions, and all subsequent releases, contain a software fix for this vulnerability: 3.9.3.0 4.5.6.0 5.0.9.0 5.1.4.100

Affected (4)

Products: Hpe: Nimbleos
1 product
Nimbleos
Configuration A
4 vulnerable · 9 platform
Vulnerable SoftwareAffected Versions
Hpe
From 3.1.0.0 to 3.9.3.0
From 4.1.0.0 to 4.5.6.0
From 5.0.1.0 to 5.0.9.0
From 5.1.0.0 to 5.1.4.100
Running on/withPlatform Versions
Hpe
Nimble Storage Af20 All Flash Array
All versions
Hpe
Nimble Storage Af20q All Flash Dual Controller
All versions
Hpe
Nimble Storage Af40 All Flash Dual Controller
All versions
Hpe
Nimble Storage Af60 All Flash Dual Controller
All versions
Hpe
Nimble Storage Af80 All Flash Dual Controller
All versions
Hpe
Nimble Storage Cs3000
All versions
Hpe
Nimble Storage Cs5000
All versions
Hpe
Nimble Storage Cs7000
All versions
Hpe
Nimble Storage Secondary Flash Arrays
All versions

Timeline

No history available yet.