10
CVSSv2

CVE-2021-26588

Published: 11/10/2021 Updated: 18/10/2021
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 Storage array firmware. An unauthenticated user could remotely exploit the low complexity issue to execute code as administrator. This vulnerability impacts completely the confidentiality, integrity, availability of the array. HPE has made the following software updates and mitigation information to resolve the vulnerability in 3PAR, Primera and Alletra 9000 firmware.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

hpe 3par_os 3.3.1_mp5_p156

hpe 3par_os 3.3.1_mu1

hpe 3par_os 3.3.1_mu2_p157

hpe 3par_os 3.3.2_ga_p_01

hpe primera_630_firmware

hpe primera_650_firmware

hpe primera_670_firmware

hpe alletra_9060_firmware

hpe alletra_9080_firmware