Vulnerability Description
A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 Storage array firmware. An unauthenticated user could remotely exploit the low complexity issue to execute code as administrator. This vulnerability impacts completely the confidentiality, integrity, availability of the array. HPE has made the following software updates and mitigation information to resolve the vulnerability in 3PAR, Primera and Alletra 9000 firmware.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hpe | 3Par Os | 3.3.1_mp5_p156 |
| Hpe | 3Par Storeserv 10400 | - |
| Hpe | 3Par Storeserv 10800 | - |
| Hpe | 3Par Storeserv 20000 | - |
| Hpe | 3Par Storeserv 7200C | - |
| Hpe | 3Par Storeserv 7400C | - |
| Hpe | 3Par Storeserv 7440C | - |
| Hpe | 3Par Storeserv 8000 | - |
| Hpe | 3Par Storeserv 9000 | - |
| Hpe | Primera 630 Firmware | >= 4.0.0, <= 4.3.3 |
| Hpe | Primera 630 | - |
| Hpe | Primera 650 Firmware | >= 4.0.0, <= 4.3.3 |
| Hpe | Primera 650 | - |
| Hpe | Primera 670 Firmware | >= 4.0.0, <= 4.3.3 |
| Hpe | Primera 670 | - |
| Hpe | Alletra 9060 Firmware | >= 9.3.0, <= 9.4.0 |
| Hpe | Alletra 9060 | - |
| Hpe | Alletra 9080 Firmware | >= 9.3.0, <= 9.4.0 |
| Hpe | Alletra 9080 | - |
References
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpeVendor Advisory
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpeVendor Advisory
FAQ
What is CVE-2021-26588?
CVE-2021-26588 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 Storage array firmware. An unauthenticated user could remotely exploit the low co...
How severe is CVE-2021-26588?
CVE-2021-26588 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-26588?
Check the references section above for vendor advisories and patch information. Affected products include: Hpe 3Par Os, Hpe 3Par Storeserv 10400, Hpe 3Par Storeserv 10800, Hpe 3Par Storeserv 20000, Hpe 3Par Storeserv 7200C.