CRITICAL · 9.8

CVE-2021-26588

A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 Storage array firmware. An unauthenticated user could remotely exploit the low co...

Vulnerability Description

A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 Storage array firmware. An unauthenticated user could remotely exploit the low complexity issue to execute code as administrator. This vulnerability impacts completely the confidentiality, integrity, availability of the array. HPE has made the following software updates and mitigation information to resolve the vulnerability in 3PAR, Primera and Alletra 9000 firmware.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
Hpe3Par Os3.3.1_mp5_p156
Hpe3Par Storeserv 10400-
Hpe3Par Storeserv 10800-
Hpe3Par Storeserv 20000-
Hpe3Par Storeserv 7200C-
Hpe3Par Storeserv 7400C-
Hpe3Par Storeserv 7440C-
Hpe3Par Storeserv 8000-
Hpe3Par Storeserv 9000-
HpePrimera 630 Firmware>= 4.0.0, <= 4.3.3
HpePrimera 630-
HpePrimera 650 Firmware>= 4.0.0, <= 4.3.3
HpePrimera 650-
HpePrimera 670 Firmware>= 4.0.0, <= 4.3.3
HpePrimera 670-
HpeAlletra 9060 Firmware>= 9.3.0, <= 9.4.0
HpeAlletra 9060-
HpeAlletra 9080 Firmware>= 9.3.0, <= 9.4.0
HpeAlletra 9080-

References

FAQ

What is CVE-2021-26588?

CVE-2021-26588 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 Storage array firmware. An unauthenticated user could remotely exploit the low co...

How severe is CVE-2021-26588?

CVE-2021-26588 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2021-26588?

Check the references section above for vendor advisories and patch information. Affected products include: Hpe 3Par Os, Hpe 3Par Storeserv 10400, Hpe 3Par Storeserv 10800, Hpe 3Par Storeserv 20000, Hpe 3Par Storeserv 7200C.