← Back

CVE-2022-28618

nvd nist
Published: May 20, 2022Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

A command injection security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays and HPE Nimble Storage Secondary Flash Arrays that could allow an attacker to execute arbitrary commands on a Nimble appliance. HPE has made the following software updates to resolve the vulnerability in HPE Nimble Storage: 5.0.10.100 or later, 5.2.1.0 or later, 6.0.0.100 or later.

Affected (3)

Products: Hpe: Nimbleos
1 product
Nimbleos
Configuration A
3 vulnerable · 3 platform
Vulnerable SoftwareAffected Versions
Hpe
Before 5.0.10.100
From 5.1.0.0 to 5.2.1.500
From 5.3.0.0 to 6.0.0.100
Running on/withPlatform Versions
Hpe
Nimble Storage All Flash Arrays
All versions
Hpe
Nimble Storage Hybrid Flash Arrays
All versions
Hpe
Nimble Storage Secondary Flash Arrays
All versions

Timeline

No history available yet.