Lucene search

K
cveHpeCVE-2023-30908
HistorySep 07, 2023 - 10:15 p.m.

CVE-2023-30908

2023-09-0722:15:07
hpe
web.nvd.nist.gov
55
cve-2023-30908
remote
authentication bypass
oneview api
nvd
security

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.004

Percentile

73.8%

A remote authentication bypass issue exists in a OneView API.

Affected configurations

Nvd
Node
hponeviewRange<6.60.05
OR
hponeviewRange7.08.5
VendorProductVersionCPE
hponeview*cpe:2.3:a:hp:oneview:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "HPE OneView",
    "vendor": "Hewlett Packard Enterprise (HPE)",
    "versions": [
      {
        "lessThan": "8.5",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      },
      {
        "lessThan": "6.60.05 LTS",
        "status": "affected",
        "version": "0",
        "versionType": "custom0"
      }
    ]
  }
]

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.004

Percentile

73.8%

Related for CVE-2023-30908