Remote Authorization Bypass in HPE 3PAR StoreServ Management and Core Software
CVE-2019-5405
7.3HIGH
Key Information:
- Vendor
- HP
- Vendor
- CVE Published:
- 9 August 2019
Summary
A remote authorization bypass vulnerability was identified in HPE 3PAR StoreServ Management and Core Software. This flaw allows unauthorized users to gain access to sensitive functions and resources that should be protected. It impacts versions prior to 3.5.0.1, posing significant risks to data integrity and security. Organizations using affected versions are advised to update to the latest software to mitigate this vulnerability.
Affected Version(s)
HPE 3PAR StoreServ Management and Core Software Media prior to 3.5.0.1
References
CVSS V3.1
Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved