Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-7198

Опубликовано: 06 нояб. 2020
Источник: nvd
CVSS3: 8.8
CVSS2: 6.5
EPSS Низкий

Описание

There is a remote escalation of privilege possible for a malicious user that has a OneView account in OneView and Synergy Composer. HPE has provided updates to Oneview and Synergy Composer: Update to version 5.5 of OneView, Composer, or Composer2.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:hp:oneview:5.0:*:*:*:*:*:*:*
cpe:2.3:a:hp:oneview:5.00.01:*:*:*:*:*:*:*
cpe:2.3:a:hp:oneview:5.00.02:*:*:*:*:*:*:*
cpe:2.3:a:hp:oneview:5.2:*:*:*:*:*:*:*
cpe:2.3:a:hp:oneview:5.3:*:*:*:*:*:*:*
cpe:2.3:a:hp:oneview:5.4:*:*:*:*:*:*:*
cpe:2.3:a:hp:oneview:5.20.01:*:*:*:*:*:*:*
cpe:2.3:a:hp:synergy_composer:5.0:*:*:*:*:*:*:*
cpe:2.3:a:hp:synergy_composer:5.00.01:*:*:*:*:*:*:*
cpe:2.3:a:hp:synergy_composer:5.00.02:*:*:*:*:*:*:*
cpe:2.3:a:hp:synergy_composer:5.2:*:*:*:*:*:*:*
cpe:2.3:a:hp:synergy_composer:5.3:*:*:*:*:*:*:*
cpe:2.3:a:hp:synergy_composer:5.4:*:*:*:*:*:*:*
cpe:2.3:a:hp:synergy_composer:5.20.01:*:*:*:*:*:*:*
cpe:2.3:a:hp:synergy_composer_2:5.0:*:*:*:*:*:*:*
cpe:2.3:a:hp:synergy_composer_2:5.00.01:*:*:*:*:*:*:*
cpe:2.3:a:hp:synergy_composer_2:5.00.02:*:*:*:*:*:*:*
cpe:2.3:a:hp:synergy_composer_2:5.2:*:*:*:*:*:*:*
cpe:2.3:a:hp:synergy_composer_2:5.3:*:*:*:*:*:*:*
cpe:2.3:a:hp:synergy_composer_2:5.4:*:*:*:*:*:*:*
cpe:2.3:a:hp:synergy_composer_2:5.20.01:*:*:*:*:*:*:*

EPSS

Процентиль: 63%
0.00446
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

github
больше 3 лет назад

There is a remote escalation of privilege possible for a malicious user that has a OneView account in OneView and Synergy Composer. HPE has provided updates to Oneview and Synergy Composer: Update to version 5.5 of OneView, Composer, or Composer2.

EPSS

Процентиль: 63%
0.00446
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

NVD-CWE-noinfo