CVE-2020-7139
8.1
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Exploitability: 2.8 / Impact: 5.2
Source: NVD
Description
Potential remote access security vulnerabilities have been identified with HPE Nimble Storage systems that could be exploited by an attacker to access and modify sensitive information on the system. The following NimbleOS versions, and all subsequent releases, contain a software fix for this vulnerability: 3.9.3.0 4.5.6.0 5.0.9.0 5.1.4.100
Affected (4)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.1.0.0 to 3.9.3.0 |
| Running on/with | Platform Versions |
|---|---|
Hpe Nimble Storage Af20 All Flash Array | All versions |
Hpe Nimble Storage Af20q All Flash Dual Controller | All versions |
Hpe Nimble Storage Af40 All Flash Dual Controller | All versions |
Hpe Nimble Storage Af60 All Flash Dual Controller | All versions |
Hpe Nimble Storage Af80 All Flash Dual Controller | All versions |
Hpe Nimble Storage Cs3000 | All versions |
Hpe Nimble Storage Cs5000 | All versions |
Hpe Nimble Storage Cs7000 | All versions |
Hpe Nimble Storage Secondary Flash Arrays | All versions |
References (2)
Source: security-alert@hpe.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.