Remote Access Vulnerability in HPE Nimble Storage Systems
CVE-2020-7139

8.1HIGH

What is CVE-2020-7139?

Potential remote access vulnerabilities have been discovered in HPE Nimble Storage systems, enabling attackers to gain unauthorized access and modify sensitive data. This issue impacts multiple versions of NimbleOS, which are outlined in the latest software update provided by HPE. Organizations using affected systems should ensure they are updated to the patched versions to mitigate risks associated with unauthorized data access.

Affected Version(s)

HPE Nimble Storage Hybrid Flash Arrays; Nimble Storage All Flash Arrays; Nimble Storage Secondary Flash Arrays 3.9.2.0 and older, 4.5.5.0 and older, 5.0.8.0 and older, 5.1.4.0 and older

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.