CVE-2019-11996
Potential security vulnerabilities have been identified with HPE Nimble Storage systems in multi array group configurations. The vulnerabilities could be exploited by an attacker to gain elevated privileges on the array. The following NimbleOS versions, and all subsequent releases, contain a software fix for this vulnerability: 3.9.2.0, 4.5.5.0, 5.0.8.0 and 5.1.3.0.
Published:Nov 7, 2019
Last Modified:Nov 21, 2024
EPS:Nov 7, 2019
EPSS Score:0.00442
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Hpe
Product
Nimble Storage Af20 All Flash Array
Hpe
Nimble Storage Af20 All Flash Array
Vendor
Hpe
Product
Nimble Storage Af20q All Flash Dual Controller
Hpe
Nimble Storage Af20q All Flash Dual Controller
Vendor
Hpe
Product
Nimble Storage Af40 All Flash Dual Controller
Hpe
Nimble Storage Af40 All Flash Dual Controller
Vendor
Hpe
Product
Nimble Storage Af60 All Flash Dual Controller
Hpe
Nimble Storage Af60 All Flash Dual Controller
Vendor
Hpe
Product
Nimble Storage Af80 All Flash Dual Controller
Hpe
Nimble Storage Af80 All Flash Dual Controller
Vendor
Hpe
Product
Nimble Storage Cs3000
Hpe
Nimble Storage Cs3000
Vendor
Hpe
Product
Nimble Storage Cs5000
Hpe
Nimble Storage Cs5000
Vendor
Hpe
Product
Nimble Storage Cs7000
Hpe
Nimble Storage Cs7000
Vendor
Hpe
Product
Nimble Storage Secondary Flash Arrays
Hpe
Nimble Storage Secondary Flash Arrays
Vendor
Hpe
Product
Nimbleos
Hpe
Nimbleos
Exploits
No exploit reference
Common Weakness Enumeration
No CWE recorded yet
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
