HIGH · 8.0

CVE-2022-37928

Insufficient Verification of Data Authenticity vulnerability in Hewlett Packard Enterprise HPE Nimble Storage Hybrid Flash Arrays and Nimble Storage Secondary Flash Arrays.

Vulnerability Description

Insufficient Verification of Data Authenticity vulnerability in Hewlett Packard Enterprise HPE Nimble Storage Hybrid Flash Arrays and Nimble Storage Secondary Flash Arrays.

CVSS Score

8.0

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
HpeSf100 Firmware< 5.2.1.900
HpeSf100-
HpeSf300 Firmware< 5.2.1.900
HpeSf300-
HpeHf60C Firmware< 5.2.1.900
HpeHf60C-
HpeHf40C Firmware< 5.2.1.900
HpeHf40C-
HpeHf20 Firmware< 5.2.1.900
HpeHf20-
HpeHf40 Firmware< 5.2.1.900
HpeHf40-
HpeHf60 Firmware< 5.2.1.900
HpeHf60-
HpeHf20H Firmware< 5.2.1.900
HpeHf20H-
HpeHf20C Firmware< 5.2.1.900
HpeHf20C-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-37928?

CVE-2022-37928 is a vulnerability with a CVSS score of 8.0 (HIGH). Insufficient Verification of Data Authenticity vulnerability in Hewlett Packard Enterprise HPE Nimble Storage Hybrid Flash Arrays and Nimble Storage Secondary Flash Arrays.

How severe is CVE-2022-37928?

CVE-2022-37928 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-37928?

Check the references section above for vendor advisories and patch information. Affected products include: Hpe Sf100 Firmware, Hpe Sf100, Hpe Sf300 Firmware, Hpe Sf300, Hpe Hf60C Firmware.