Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-23703

Опубликовано: 12 апр. 2022
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

A security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays and HPE Nimble Storage Secondary Flash Arrays during update. This would potentially allow an attacker to intercept and modify network communication for software updates initiated by the Nimble appliance. The following NimbleOS versions, and all subsequent releases, contain a software fix for this vulnerability: 5.0.10.100, 5.2.1.500, 6.0.0.100

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:o:hpe:nimbleos:*:*:*:*:*:*:*:*
Версия до 5.0.10.100 (исключая)
cpe:2.3:o:hpe:nimbleos:*:*:*:*:*:*:*:*
Версия от 5.1.0.0 (включая) до 5.2.1.500 (исключая)
cpe:2.3:o:hpe:nimbleos:5.3.1.0:*:*:*:*:*:*:*

EPSS

Процентиль: 47%
0.00241
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 7.5
github
почти 4 года назад

A security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays and HPE Nimble Storage Secondary Flash Arrays during update. This would potentially allow an attacker to intercept and modify network communication for software updates initiated by the Nimble appliance. The following NimbleOS versions, and all subsequent releases, contain a software fix for this vulnerability: 5.0.10.100, 5.2.1.500, 6.0.0.100

EPSS

Процентиль: 47%
0.00241
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

NVD-CWE-noinfo