CVE-2022-23705
Last modified
CVE-2022-23705 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays, and HPE Nimble Storage Secondary Flash Arrays which could potentially allow the upload, but not execution, of unauthorized update binaries to the array. HPE has made the following software updates to resolve the vulnerability in HPE Nimble Storage: 5.0.10.100 or later, 5.2.1.0 or later, 6.0.0.100 or later.. EPSS estimates a 0.98% chance of exploitation in the next 30 days.
Description
A security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays, and HPE Nimble Storage Secondary Flash Arrays which could potentially allow the upload, but not execution, of unauthorized update binaries to the array. HPE has made the following software updates to resolve the vulnerability in HPE Nimble Storage: 5.0.10.100 or later, 5.2.1.0 or later, 6.0.0.100 or later.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hpe | Nimbleos | < 5.0.10.100 |
| Hpe | Nimbleos | >= 5.1.0.0, < 5.2.1.500 |
| Hpe | Nimbleos | 5.3.1.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-23705?
How severe is CVE-2022-23705?
How do I fix CVE-2022-23705?
Are you affected by CVE-2022-23705?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
