Lucene search

K
cvelistHpeCVELIST:CVE-2022-28618
HistoryMay 20, 2022 - 8:50 p.m.

CVE-2022-28618

2022-05-2020:50:19
hpe
www.cve.org
2
hpe nimble storage
command injection
security vulnerability
software updates

AI Score

10

Confidence

High

EPSS

0.001

Percentile

43.7%

A command injection security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays and HPE Nimble Storage Secondary Flash Arrays that could allow an attacker to execute arbitrary commands on a Nimble appliance. HPE has made the following software updates to resolve the vulnerability in HPE Nimble Storage: 5.0.10.100 or later, 5.2.1.0 or later, 6.0.0.100 or later.

CNA Affected

[
  {
    "product": "HPE Nimble Storage Hybrid Flash Arrays; Nimble Storage All Flash Arrays; Nimble Storage Secondary Flash Arrays",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "5.0.10.0 and earlier"
      },
      {
        "status": "affected",
        "version": "5.2.1.400 and earlier"
      },
      {
        "status": "affected",
        "version": "and 5.3.1.0 and earlier"
      }
    ]
  }
]

AI Score

10

Confidence

High

EPSS

0.001

Percentile

43.7%

Related for CVELIST:CVE-2022-28618