VYPR
Medium severity5.9NVD Advisory· Published Sep 27, 2018· Updated Jun 17, 2026

CVE-2018-7108

CVE-2018-7108

Description

HPE StorageWorks XP7 Automation Director (AutoDir) version 8.5.2-02 to earlier than 8.6.1-00 has a local and remote authentication bypass vulnerability that exposed the user authentication information of the storage system. This problem sometimes occurred under specific conditions when running a service template.

Affected products

3
  • cpe:2.3:a:hpe:storageworks_xp7_automation_director:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:hpe:storageworks_xp7_automation_director:*:*:*:*:*:*:*:*range: >=8.5.2-02,<8.6.1-00
    • (no CPE)range: >=8.5.2-02 <8.6.1-00
  • Hewlett Packard Enterprise/HPE StorageWorks XP7 Automation Director (AutoDir)v5
    Range: version 8.5.2-02 to earlier than 8.6.1-00

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.