HIGH · 8.8

CVE-2020-7138

Potential remote code execution security vulnerabilities have been identified with HPE Nimble Storage systems that could be exploited by an attacker to gain elevated privileges on the array. The follo...

Vulnerability Description

Potential remote code execution security vulnerabilities have been identified with HPE Nimble Storage systems that could be exploited by an attacker to gain elevated privileges on the array. The following NimbleOS versions, and all subsequent releases, contain a software fix for this vulnerability: 3.9.3.0 4.5.6.0 5.0.9.0 5.1.4.100

CVSS Score

8.8

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
HpeNimbleos>= 3.1.0.0, <= 3.9.3.0
HpeNimble Storage Af20 All Flash Array-
HpeNimble Storage Af20Q All Flash Dual Controller-
HpeNimble Storage Af40 All Flash Dual Controller-
HpeNimble Storage Af60 All Flash Dual Controller-
HpeNimble Storage Af80 All Flash Dual Controller-
HpeNimble Storage Cs3000-
HpeNimble Storage Cs5000-
HpeNimble Storage Cs7000-
HpeNimble Storage Secondary Flash Arrays-

References

FAQ

What is CVE-2020-7138?

CVE-2020-7138 is a vulnerability with a CVSS score of 8.8 (HIGH). Potential remote code execution security vulnerabilities have been identified with HPE Nimble Storage systems that could be exploited by an attacker to gain elevated privileges on the array. The follo...

How severe is CVE-2020-7138?

CVE-2020-7138 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-7138?

Check the references section above for vendor advisories and patch information. Affected products include: Hpe Nimbleos, Hpe Nimble Storage Af20 All Flash Array, Hpe Nimble Storage Af20Q All Flash Dual Controller, Hpe Nimble Storage Af40 All Flash Dual Controller, Hpe Nimble Storage Af60 All Flash Dual Controller.