CVE-2020-7197
Last modified
CVE-2020-7197 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. SSMC3.7.0.0 is vulnerable to remote authentication bypass. HPE StoreServ Management Console (SSMC) 3.7.0.0 is an off node multiarray manager web application and remains isolated from data on the managed arrays. EPSS estimates a 2.15% chance of exploitation in the next 30 days.
Description
SSMC3.7.0.0 is vulnerable to remote authentication bypass. HPE StoreServ Management Console (SSMC) 3.7.0.0 is an off node multiarray manager web application and remains isolated from data on the managed arrays. HPE has provided an update to HPE StoreServ Management Console (SSMC) software 3.7.0.0* Upgrade to HPE 3PAR StoreServ Management Console 3.7.1.1 or later.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hp | Storeserv Management Console | < 3.7.1.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-7197?
How severe is CVE-2020-7197?
How do I fix CVE-2020-7197?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-7191A devsoftsel expression language injection remote code execu…8.8
- CVE-2020-7192A devicethresholdconfig expression language injection remote…8.8
- CVE-2020-7193A ictexpertcsvdownload expression language injection remote …8.8
- CVE-2020-7194A perfaddormoddevicemonitor expression language injection re…8.8
- CVE-2020-7195A iccselectrules expression language injection remote code e…8.8
- CVE-2020-7196The HPE BlueData EPIC Software Platform version 4.0 and HPE …6.5
- CVE-2020-7198There is a remote escalation of privilege possible for a mal…8.8
- CVE-2020-7199A security vulnerability has been identified in the HPE Edge…9.8
- CVE-2020-7200A potential security vulnerability has been identified in HP…9.8
- CVE-2020-7201A potential security vulnerability has been identified in th…8.8
- CVE-2020-7202A potential security vulnerability has been identified in HP…5.3
- CVE-2020-7203A potential security vulnerability has been identified in HP…9.8
Are you affected by CVE-2020-7197?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
