← Back

CVE-2021-26587

nvd nist
Published: Sep 27, 2021Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Exploitability: 2.3 / Impact: 3.7
Source: NVD

Description

A potential DOM-based Cross Site Scripting security vulnerability has been identified in HPE StoreOnce. The vulnerability could be remotely exploited to cause an elevation of privilege leading to partial impact to confidentiality, availability, and integrity. HPE has made the following software update - HPE StoreOnce 4.3.0, to resolve the vulnerability in HPE StoreOnce.

Affected (6)

6 products
Storeonce 5200 Firmware
Storeonce 5650 Firmware
Storeonce 5250 Firmware
Storeonce 3640 Firmware
Storeonce 3620 Firmware
Storeonce Vsa 4tb Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 4.2.3
Running on/withPlatform Versions
Hpe
Storeonce 5200
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 4.2.3
Running on/withPlatform Versions
Hpe
Storeonce 5650
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 4.2.3
Running on/withPlatform Versions
Hpe
Storeonce 5250
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 4.2.3
Running on/withPlatform Versions
Hpe
Storeonce 3640
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 4.2.3
Running on/withPlatform Versions
Hpe
Storeonce 3620
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 4.2.3
Running on/withPlatform Versions
Hpe
Storeonce Vsa 4tb
All versions

Timeline

No history available yet.