VYPR

NimbleOS

by HPE

CVEs (6)

  • CVE-2022-28618CriMay 20, 2022
    risk 0.64cvss 9.8epss 0.02

    A command injection security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays and HPE Nimble Storage Secondary Flash Arrays that could allow an attacker to execute arbitrary commands on a Nimble appliance. HPE has…

  • CVE-2019-11996CriNov 7, 2019
    risk 0.64cvss 9.8epss 0.01

    Potential security vulnerabilities have been identified with HPE Nimble Storage systems in multi array group configurations. The vulnerabilities could be exploited by an attacker to gain elevated privileges on the array. The following NimbleOS versions, and all subsequent…

  • CVE-2020-7138HigMay 19, 2020
    risk 0.57cvss 8.8epss 0.02

    Potential remote code execution security vulnerabilities have been identified with HPE Nimble Storage systems that could be exploited by an attacker to gain elevated privileges on the array. The following NimbleOS versions, and all subsequent releases, contain a software fix for…

  • CVE-2020-7139HigMay 19, 2020
    risk 0.53cvss 8.1epss 0.01

    Potential remote access security vulnerabilities have been identified with HPE Nimble Storage systems that could be exploited by an attacker to access and modify sensitive information on the system. The following NimbleOS versions, and all subsequent releases, contain a software…

  • CVE-2022-23705HigMay 9, 2022
    risk 0.49cvss 7.5epss 0.01

    A security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays, and HPE Nimble Storage Secondary Flash Arrays which could potentially allow the upload, but not execution, of unauthorized update binaries to the array.…

  • CVE-2022-23703HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.01

    A security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays and HPE Nimble Storage Secondary Flash Arrays during update. This would potentially allow an attacker to intercept and modify network communication for…