Unauthorized Binary Upload Vulnerability in HPE Nimble Storage Products
CVE-2022-23705

7.5HIGH

What is CVE-2022-23705?

A security vulnerability exists within HPE Nimble Storage systems that may permit the upload of unauthorized update binaries to the storage arrays. This could lead to potential manipulation or deceptive behavior in the storage environment. HPE has addressed this issue in software updates, which are available in versions 5.0.10.100 or later, 5.2.1.0 or later, and 6.0.0.100 or later, ensuring stronger security protocols for users.

Affected Version(s)

HPE Nimble Storage Hybrid Flash Arrays; Nimble Storage All Flash Arrays; Nimble Storage Secondary Flash Arrays 5.0.10.0 and earlier

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.