CVE Feed

    Dashboard / CVE / CVE-2021-26588

    CVE-2021-26588

    A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 Storage array firmware. An unauthenticated user could remotely exploit the low complexity issue to execute code as administrator. This vulnerability impacts completely the confidentiality, integrity, availability of the array. HPE has made the following software updates and mitigation information to resolve the vulnerability in 3PAR, Primera and Alletra 9000 firmware.

    Published:Oct 11, 2021
    Last Modified:Nov 21, 2024
    EPS:Oct 11, 2021
    EPSS Score:0.01708
    CVSS Score:9.8

    Affected Products

    Vendor
    Hpe
    Product
    3par Os
    Vendor
    Hpe
    Product
    3par Storeserv 10400
    Vendor
    Hpe
    Product
    3par Storeserv 10800
    Vendor
    Hpe
    Product
    3par Storeserv 20000
    Vendor
    Hpe
    Product
    3par Storeserv 7200c
    Vendor
    Hpe
    Product
    3par Storeserv 7400c
    Vendor
    Hpe
    Product
    3par Storeserv 7440c
    Vendor
    Hpe
    Product
    3par Storeserv 8000
    Vendor
    Hpe
    Product
    3par Storeserv 9000
    Vendor
    Hpe
    Product
    Alletra 9060
    Vendor
    Hpe
    Product
    Alletra 9060 Firmware
    Vendor
    Hpe
    Product
    Alletra 9080
    Vendor
    Hpe
    Product
    Alletra 9080 Firmware
    Vendor
    Hpe
    Product
    Primera 630
    Vendor
    Hpe
    Product
    Primera 630 Firmware
    Vendor
    Hpe
    Product
    Primera 650
    Vendor
    Hpe
    Product
    Primera 650 Firmware
    Vendor
    Hpe
    Product
    Primera 670
    Vendor
    Hpe
    Product
    Primera 670 Firmware

    Exploits

    No exploit reference

    Common Weakness Enumeration

    No CWE recorded yet

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High