MEDIUM · 6.7

CVE-2022-37929

Improper Privilege Management vulnerability in Hewlett Packard Enterprise Nimble Storage Hybrid Flash Arrays and Nimble Storage Secondary Flash Arrays.

Vulnerability Description

Improper Privilege Management vulnerability in Hewlett Packard Enterprise Nimble Storage Hybrid Flash Arrays and Nimble Storage Secondary Flash Arrays.

CVSS Score

6.7

MEDIUM

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
HpeSf100 Firmware< 5.2.1.900
HpeSf100-
HpeSf300 Firmware< 5.2.1.900
HpeSf300-
HpeHf60C Firmware< 5.2.1.900
HpeHf60C-
HpeHf40C Firmware< 5.2.1.900
HpeHf40C-
HpeHf20 Firmware< 5.2.1.900
HpeHf20-
HpeHf40 Firmware< 5.2.1.900
HpeHf40-
HpeHf60 Firmware< 5.2.1.900
HpeHf60-
HpeHf20H Firmware< 5.2.1.900
HpeHf20H-
HpeHf20C Firmware< 5.2.1.900
HpeHf20C-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-37929?

CVE-2022-37929 is a vulnerability with a CVSS score of 6.7 (MEDIUM). Improper Privilege Management vulnerability in Hewlett Packard Enterprise Nimble Storage Hybrid Flash Arrays and Nimble Storage Secondary Flash Arrays.

How severe is CVE-2022-37929?

CVE-2022-37929 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-37929?

Check the references section above for vendor advisories and patch information. Affected products include: Hpe Sf100 Firmware, Hpe Sf100, Hpe Sf300 Firmware, Hpe Sf300, Hpe Hf60C Firmware.