CVE-2019-5408
Command View Advanced Edition (CVAE) products contain a vulnerability that could expose configuration information of hosts and storage systems that are managed by Device Manager server. This problem is due to a vulnerability in Device Manager GUI. The following products are affected. DevMgr version 7.0.0-00 to earlier than 8.6.1-02 RepMgr if it is installed on the same machine as DevMgr TSMgr if it is installed on the same machine as DevMgr. The resolution is to upgrade to the fixed version as described below or later version of DevMgr 8.6.2-02 or later. RepMgr and TSMgr will be corrected by upgrading DevMgr.
Published:Aug 9, 2019
Last Modified:Nov 21, 2024
EPS:Aug 9, 2019
EPSS Score:0.00546
CVSS Score:6.5
Affected Products
Vendor
Product
Action
Vendor
Hp
Product
Xp7 Device Manager
Hp
Xp7 Device Manager
Vendor
Hp
Product
Xp7 Replication Manager
Hp
Xp7 Replication Manager
Vendor
Hp
Product
Xp7 Tiered Storage Manager
Hp
Xp7 Tiered Storage Manager
Exploits
No exploit reference
Common Weakness Enumeration
No CWE recorded yet
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
