Local Authentication Restriction Bypass in HPE OneView
CVE-2022-23699

7.8HIGH

Key Information:

Vendor
HP
Vendor
CVE Published:
4 April 2022

Summary

A local authentication restriction bypass vulnerability was identified in HPE OneView versions prior to 6.6. This flaw enables unauthorized local access to the system, thereby potentially allowing malicious users to exploit sensitive functionalities without proper credentials. To mitigate this issue, HPE has released a software update, urging users to upgrade their systems to enhance security.

Affected Version(s)

HPE OneView Prior to 6.6

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.