CVE-2021-26588
A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 Storage array firmware. An unauthenticated user could remotely exploit the low complexity issue to execute code as administrator. This vulnerability impacts completely the confidentiality, integrity, availability of the array. HPE has made the following software updates and mitigation information to resolve the vulnerability in 3PAR, Primera and Alletra 9000 firmware.
Published:Oct 11, 2021
Last Modified:Nov 21, 2024
EPS:Oct 11, 2021
EPSS Score:0.01708
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Hpe
Product
3par Os
Hpe
3par Os
Vendor
Hpe
Product
3par Storeserv 10400
Hpe
3par Storeserv 10400
Vendor
Hpe
Product
3par Storeserv 10800
Hpe
3par Storeserv 10800
Vendor
Hpe
Product
3par Storeserv 20000
Hpe
3par Storeserv 20000
Vendor
Hpe
Product
3par Storeserv 7200c
Hpe
3par Storeserv 7200c
Vendor
Hpe
Product
3par Storeserv 7400c
Hpe
3par Storeserv 7400c
Vendor
Hpe
Product
3par Storeserv 7440c
Hpe
3par Storeserv 7440c
Vendor
Hpe
Product
3par Storeserv 8000
Hpe
3par Storeserv 8000
Vendor
Hpe
Product
3par Storeserv 9000
Hpe
3par Storeserv 9000
Vendor
Hpe
Product
Alletra 9060
Hpe
Alletra 9060
Vendor
Hpe
Product
Alletra 9060 Firmware
Hpe
Alletra 9060 Firmware
Vendor
Hpe
Product
Alletra 9080
Hpe
Alletra 9080
Vendor
Hpe
Product
Alletra 9080 Firmware
Hpe
Alletra 9080 Firmware
Vendor
Hpe
Product
Primera 630
Hpe
Primera 630
Vendor
Hpe
Product
Primera 630 Firmware
Hpe
Primera 630 Firmware
Vendor
Hpe
Product
Primera 650
Hpe
Primera 650
Vendor
Hpe
Product
Primera 650 Firmware
Hpe
Primera 650 Firmware
Vendor
Hpe
Product
Primera 670
Hpe
Primera 670
Vendor
Hpe
Product
Primera 670 Firmware
Hpe
Primera 670 Firmware
Exploits
No exploit reference
Common Weakness Enumeration
No CWE recorded yet
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
