CVE-2021-26588
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 Storage array firmware. An unauthenticated user could remotely exploit the low complexity issue to execute code as administrator. This vulnerability impacts completely the confidentiality, integrity, availability of the array. HPE has made the following software updates and mitigation information to resolve the vulnerability in 3PAR, Primera and Alletra 9000 firmware.
Affected (9)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.3.1_mp5_p156 |
| Running on/with | Platform Versions |
|---|---|
Hpe 3par Storeserv 10400 | All versions |
Hpe 3par Storeserv 10800 | All versions |
Hpe 3par Storeserv 20000 | All versions |
Hpe 3par Storeserv 7200c | All versions |
Hpe 3par Storeserv 7400c | All versions |
Hpe 3par Storeserv 7440c | All versions |
Hpe 3par Storeserv 8000 | All versions |
Hpe 3par Storeserv 9000 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.0.0 to 4.3.3 |
| Running on/with | Platform Versions |
|---|---|
Hpe Primera 630 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.0.0 to 4.3.3 |
| Running on/with | Platform Versions |
|---|---|
Hpe Primera 650 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.0.0 to 4.3.3 |
| Running on/with | Platform Versions |
|---|---|
Hpe Primera 670 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| From 9.3.0 to 9.4.0 |
| Running on/with | Platform Versions |
|---|---|
Hpe Alletra 9060 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| From 9.3.0 to 9.4.0 |
| Running on/with | Platform Versions |
|---|---|
Hpe Alletra 9080 | All versions |
References (2)
Source: security-alert@hpe.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.