Local Data Injection Vulnerability in HPE Superdome Flex and Superdome Flex 280 Servers
CVE-2022-37933

7.3HIGH

Key Information:

Vendor
HP
Vendor
CVE Published:
5 January 2023

Summary

A potential security vulnerability exists in the HPE Superdome Flex and Superdome Flex 280 servers that could be exploited by local attackers. This vulnerability allows unauthorized data injection, posing a significant risk to data integrity. HPE has released firmware updates to mitigate this issue, specifically in Superdome Flex firmware versions 3.60.50 and below, as well as Superdome Flex 280 servers on firmware versions 1.40.60 and below. Users are advised to apply these updates promptly to protect their systems.

Affected Version(s)

HPE Superdome Flex Server; HPE Superdome Flex 280 Server Prior to 3.60.50; Prior to 1.40.60

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.