Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-23705

Опубликовано: 09 мая 2022
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

A security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays, and HPE Nimble Storage Secondary Flash Arrays which could potentially allow the upload, but not execution, of unauthorized update binaries to the array. HPE has made the following software updates to resolve the vulnerability in HPE Nimble Storage: 5.0.10.100 or later, 5.2.1.0 or later, 6.0.0.100 or later.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:o:hpe:nimbleos:*:*:*:*:*:*:*:*
Версия до 5.0.10.100 (исключая)
cpe:2.3:o:hpe:nimbleos:*:*:*:*:*:*:*:*
Версия от 5.1.0.0 (включая) до 5.2.1.500 (исключая)
cpe:2.3:o:hpe:nimbleos:5.3.1.0:*:*:*:*:*:*:*

EPSS

Процентиль: 65%
0.00493
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 7.5
github
больше 3 лет назад

A security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays, and HPE Nimble Storage Secondary Flash Arrays which could potentially allow the upload, but not execution, of unauthorized update binaries to the array. HPE has made the following software updates to resolve the vulnerability in HPE Nimble Storage: 5.0.10.100 or later, 5.2.1.0 or later, 6.0.0.100 or later.

EPSS

Процентиль: 65%
0.00493
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

NVD-CWE-noinfo