Remote Authorization Bypass in HPE 3PAR StoreServ Management and Core Software
CVE-2019-5405

7.3HIGH

Key Information:

Vendor
HP
Vendor
CVE Published:
9 August 2019

Summary

A remote authorization bypass vulnerability was identified in HPE 3PAR StoreServ Management and Core Software. This flaw allows unauthorized users to gain access to sensitive functions and resources that should be protected. It impacts versions prior to 3.5.0.1, posing significant risks to data integrity and security. Organizations using affected versions are advised to update to the latest software to mitigate this vulnerability.

Affected Version(s)

HPE 3PAR StoreServ Management and Core Software Media prior to 3.5.0.1

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.