Insufficient Verification of Data Authenticity in HPE Nimble Storage Products
CVE-2022-37928

6.5MEDIUM

What is CVE-2022-37928?

A vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays and Nimble Storage Secondary Flash Arrays, stemming from insufficient verification of data authenticity. This flaw could allow attackers to manipulate data without proper validation, potentially leading to unauthorized access or data corruption. It is crucial for organizations using these systems to assess their environments and implement necessary safeguards to protect against potential exploitation.

Affected Version(s)

HPE Nimble Storage Hybrid Flash Arrays; Nimble Storage Secondary Flash Arrays Prior to 5.2.1.900 (LTSR), 5.3.0.0 (GA)

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.