Remote Session Reuse Vulnerability in HPE MSA SAN Storage
CVE-2019-12001

6.4MEDIUM

Summary

A vulnerability has been identified in HPE MSA SAN Storage that permits remote session reuse, potentially allowing unauthorized users to bypass access restrictions. This issue affects various models, including the HPE MSA 2040 and MSA 1040, with impacted versions being GL225P001 and earlier, and VE270R001-01 and earlier for other models. Organizations using these products should review their security configuration and apply recommended patches to mitigate potential risks.

Affected Version(s)

HPE MSA 2040 SAN Storage; HPE MSA 1040 SAN Storage; HPE MSA 1050 SAN Storage; HPE MSA 2042 SAN Storage; HPE MSA 2050 SAN Storage; HPE MSA 2052 SAN Storage HPE MSA 1040 SAN Storage GL225P001 and earlier

HPE MSA 2040 SAN Storage; HPE MSA 1040 SAN Storage; HPE MSA 1050 SAN Storage; HPE MSA 2042 SAN Storage; HPE MSA 2050 SAN Storage; HPE MSA 2052 SAN Storage HPE MSA 2040 SAN Storage GL225P001 and earlier

HPE MSA 2040 SAN Storage; HPE MSA 1040 SAN Storage; HPE MSA 1050 SAN Storage; HPE MSA 2042 SAN Storage; HPE MSA 2050 SAN Storage; HPE MSA 2052 SAN Storage HPE MSA 2042 SAN Storage GL225P001 and earlier

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.