Lucene search

K
cveHpeCVE-2019-5397
HistoryAug 09, 2019 - 6:15 p.m.

CVE-2019-5397

2019-08-0918:15:11
CWE-79
hpe
web.nvd.nist.gov
70
cve-2019-5397
remote bypass
security restrictions
vulnerability
hpe 3par service processor
nvd

CVSS2

9.7

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:P/I:C/A:C

CVSS3

9.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H

AI Score

9.1

Confidence

High

EPSS

0.002

Percentile

59.7%

A remote bypass of security restrictions vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.

Affected configurations

Nvd
Node
hp3par_service_processor_firmwareRange<5.0.5.1
AND
hp3par_service_processorMatch-
VendorProductVersionCPE
hp3par_service_processor_firmware*cpe:2.3:o:hp:3par_service_processor_firmware:*:*:*:*:*:*:*:*
hp3par_service_processor-cpe:2.3:h:hp:3par_service_processor:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "HPE 3PAR Service Processor",
    "vendor": "Hewlett Packard Enterprise (HPE)",
    "versions": [
      {
        "status": "affected",
        "version": "prior to 5.0.5.1"
      }
    ]
  }
]

CVSS2

9.7

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:P/I:C/A:C

CVSS3

9.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H

AI Score

9.1

Confidence

High

EPSS

0.002

Percentile

59.7%

Related for CVE-2019-5397