CVE-2020-7139

Potential remote access security vulnerabilities have been identified with HPE Nimble Storage systems that could be exploited by an attacker to access and modify sensitive information on the system. The following NimbleOS versions, and all subsequent releases, contain a software fix for this vulnerability: 3.9.3.0 4.5.6.0 5.0.9.0 5.1.4.100
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:hpe:nimbleos:*:*:*:*:*:*:*:*
cpe:2.3:o:hpe:nimbleos:*:*:*:*:*:*:*:*
cpe:2.3:o:hpe:nimbleos:*:*:*:*:*:*:*:*
cpe:2.3:o:hpe:nimbleos:*:*:*:*:*:*:*:*
OR cpe:2.3:h:hpe:nimble_storage_af20_all_flash_array:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:nimble_storage_af20q_all_flash_dual_controller:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:nimble_storage_af40_all_flash_dual_controller:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:nimble_storage_af60_all_flash_dual_controller:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:nimble_storage_af80_all_flash_dual_controller:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:nimble_storage_cs3000:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:nimble_storage_cs5000:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:nimble_storage_cs7000:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:nimble_storage_secondary_flash_arrays:-:*:*:*:*:*:*:*

Information

Published : 2020-05-19 23:15

Updated : 2021-07-21 11:39


NVD link : CVE-2020-7139

Mitre link : CVE-2020-7139


JSON object : View

Products Affected

hpe

  • nimble_storage_secondary_flash_arrays
  • nimbleos
  • nimble_storage_af20q_all_flash_dual_controller
  • nimble_storage_af20_all_flash_array
  • nimble_storage_af40_all_flash_dual_controller
  • nimble_storage_af80_all_flash_dual_controller
  • nimble_storage_af60_all_flash_dual_controller
  • nimble_storage_cs3000
  • nimble_storage_cs5000
  • nimble_storage_cs7000
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor