Remote Authentication Bypass in HPE 3PAR Service Processor
CVE-2019-5396

9.4CRITICAL

Key Information:

Vendor
HP
Vendor
CVE Published:
9 August 2019

Summary

A remote authentication bypass vulnerability exists in HPE 3PAR Service Processor versions earlier than 5.0.5.1, allowing unauthorized users to gain access to the system without legitimate credentials. This could lead to unauthorized exposure of sensitive data, potential manipulation of services, or administrative control of the system. It’s crucial for users to apply the latest updates to mitigate the risk associated with this vulnerability.

Affected Version(s)

HPE 3PAR Service Processor prior to 5.0.5.1

References

CVSS V3.1

Score:
9.4
Severity:
CRITICAL
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.