CVE Vulnerabilities

CVE-2019-11996

Published: Nov 07, 2019 | Modified: Aug 24, 2020
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Potential security vulnerabilities have been identified with HPE Nimble Storage systems in multi array group configurations. The vulnerabilities could be exploited by an attacker to gain elevated privileges on the array. The following NimbleOS versions, and all subsequent releases, contain a software fix for this vulnerability: 3.9.2.0, 4.5.5.0, 5.0.8.0 and 5.1.3.0.

Affected Software

Name Vendor Start Version End Version
Nimbleos Hpe 3.1.0.0 (including) 3.9.1.0 (including)
Nimbleos Hpe 4.1.0.0 (including) 4.5.4.0 (including)
Nimbleos Hpe 5.0.1.0 (including) 5.0.7.0 (including)
Nimbleos Hpe 5.1.0.0 (including) 5.1.2.0 (including)

References