9.8
CVSSv3

CVE-2022-28620

Published: 24/06/2022 Updated: 08/08/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A remote authentication bypass vulnerability exists in HPE Cray Legacy Shasta System Solutions; HPE Slingshot; and HPE Cray EX supercomputers versions: Prior to node controller firmware associated with HPE Cray EX liquid cooled blades, and all versions of chassis controller firmware associated with HPE Cray EX liquid cooled cabinets before 1.6.27/1.5.33/1.4.27; All Slingshot versions before 1.7.2; All versions of node controller firmware associated with HPE Cray EX liquid cooled blades, and all versions of chassis controller firmware associated with HPE Cray EX liquid cooled cabinets before 1.6.27/1.5.33/1.4.27. HPE has provided a software update to resolve this vulnerability in HPE Cray Legacy Shasta System Solutions, HPE Slingshot, and HPE Cray EX Supercomputers.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

hpe slingshot_firmware

hpe cray_ex_supercomputers_firmware 1.4.27

hpe cray_ex_supercomputers_firmware 1.5.33

hpe cray_ex_supercomputers_firmware 1.6.27

hpe cray_sh_supercomputer_air_cooled_base_system_code_firmware 1.4.27

hpe cray_sh_supercomputer_air_cooled_base_system_code_firmware 1.5.33

hpe cray_sh_supercomputer_air_cooled_base_system_code_firmware 1.6.27

hpe cray_sh_supercomputer_liquid_cooled_base_system_code_firmware 1.4.27

hpe cray_sh_supercomputer_liquid_cooled_base_system_code_firmware 1.5.33

hpe cray_sh_supercomputer_liquid_cooled_base_system_code_firmware 1.6.27

hpe cray_sh_supercomputer_liquid_cooled_tds_base_system_code_firmware 1.4.27

hpe cray_sh_supercomputer_liquid_cooled_tds_base_system_code_firmware 1.5.33

hpe cray_sh_supercomputer_liquid_cooled_tds_base_system_code_firmware 1.6.27