CVE-2020-7138
 
Severity Score
8.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Potential remote code execution security vulnerabilities have been identified with HPE Nimble Storage systems that could be exploited by an attacker to gain elevated privileges on the array. The following NimbleOS versions, and all subsequent releases, contain a software fix for this vulnerability: 3.9.3.0 4.5.6.0 5.0.9.0 5.1.4.100
Se han identificado potenciales vulnerabilidades de seguridad en la ejecución de código remota con los sistemas HPE Nimble Storage que podrían ser explotadas por un atacante para alcanzar privilegios elevados en la matriz. Las siguientes versiones de NimbleOS, y todas las posteriores, contienen una corrección de software para esta vulnerabilidad: 3.9.3.0 4.5.6.0 5.0.9.0 5.1.4.100
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2020-01-16 CVE Reserved
- 2020-05-19 CVE Published
- 2024-06-28 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Hpe Search vendor "Hpe" | Nimbleos Search vendor "Hpe" for product "Nimbleos" | >= 3.1.0.0 <= 3.9.3.0 Search vendor "Hpe" for product "Nimbleos" and version " >= 3.1.0.0 <= 3.9.3.0" | - |
Affected
| in | Hpe Search vendor "Hpe" | Nimble Storage Af20 All Flash Array Search vendor "Hpe" for product "Nimble Storage Af20 All Flash Array" | - | - |
Safe
|
Hpe Search vendor "Hpe" | Nimbleos Search vendor "Hpe" for product "Nimbleos" | >= 3.1.0.0 <= 3.9.3.0 Search vendor "Hpe" for product "Nimbleos" and version " >= 3.1.0.0 <= 3.9.3.0" | - |
Affected
| in | Hpe Search vendor "Hpe" | Nimble Storage Af20q All Flash Dual Controller Search vendor "Hpe" for product "Nimble Storage Af20q All Flash Dual Controller" | - | - |
Safe
|
Hpe Search vendor "Hpe" | Nimbleos Search vendor "Hpe" for product "Nimbleos" | >= 3.1.0.0 <= 3.9.3.0 Search vendor "Hpe" for product "Nimbleos" and version " >= 3.1.0.0 <= 3.9.3.0" | - |
Affected
| in | Hpe Search vendor "Hpe" | Nimble Storage Af40 All Flash Dual Controller Search vendor "Hpe" for product "Nimble Storage Af40 All Flash Dual Controller" | - | - |
Safe
|
Hpe Search vendor "Hpe" | Nimbleos Search vendor "Hpe" for product "Nimbleos" | >= 3.1.0.0 <= 3.9.3.0 Search vendor "Hpe" for product "Nimbleos" and version " >= 3.1.0.0 <= 3.9.3.0" | - |
Affected
| in | Hpe Search vendor "Hpe" | Nimble Storage Af60 All Flash Dual Controller Search vendor "Hpe" for product "Nimble Storage Af60 All Flash Dual Controller" | - | - |
Safe
|
Hpe Search vendor "Hpe" | Nimbleos Search vendor "Hpe" for product "Nimbleos" | >= 3.1.0.0 <= 3.9.3.0 Search vendor "Hpe" for product "Nimbleos" and version " >= 3.1.0.0 <= 3.9.3.0" | - |
Affected
| in | Hpe Search vendor "Hpe" | Nimble Storage Af80 All Flash Dual Controller Search vendor "Hpe" for product "Nimble Storage Af80 All Flash Dual Controller" | - | - |
Safe
|
Hpe Search vendor "Hpe" | Nimbleos Search vendor "Hpe" for product "Nimbleos" | >= 3.1.0.0 <= 3.9.3.0 Search vendor "Hpe" for product "Nimbleos" and version " >= 3.1.0.0 <= 3.9.3.0" | - |
Affected
| in | Hpe Search vendor "Hpe" | Nimble Storage Cs3000 Search vendor "Hpe" for product "Nimble Storage Cs3000" | - | - |
Safe
|
Hpe Search vendor "Hpe" | Nimbleos Search vendor "Hpe" for product "Nimbleos" | >= 3.1.0.0 <= 3.9.3.0 Search vendor "Hpe" for product "Nimbleos" and version " >= 3.1.0.0 <= 3.9.3.0" | - |
Affected
| in | Hpe Search vendor "Hpe" | Nimble Storage Cs5000 Search vendor "Hpe" for product "Nimble Storage Cs5000" | - | - |
Safe
|
Hpe Search vendor "Hpe" | Nimbleos Search vendor "Hpe" for product "Nimbleos" | >= 3.1.0.0 <= 3.9.3.0 Search vendor "Hpe" for product "Nimbleos" and version " >= 3.1.0.0 <= 3.9.3.0" | - |
Affected
| in | Hpe Search vendor "Hpe" | Nimble Storage Cs7000 Search vendor "Hpe" for product "Nimble Storage Cs7000" | - | - |
Safe
|
Hpe Search vendor "Hpe" | Nimbleos Search vendor "Hpe" for product "Nimbleos" | >= 3.1.0.0 <= 3.9.3.0 Search vendor "Hpe" for product "Nimbleos" and version " >= 3.1.0.0 <= 3.9.3.0" | - |
Affected
| in | Hpe Search vendor "Hpe" | Nimble Storage Secondary Flash Arrays Search vendor "Hpe" for product "Nimble Storage Secondary Flash Arrays" | - | - |
Safe
|
Hpe Search vendor "Hpe" | Nimbleos Search vendor "Hpe" for product "Nimbleos" | >= 4.1.0.0 <= 4.5.6.0 Search vendor "Hpe" for product "Nimbleos" and version " >= 4.1.0.0 <= 4.5.6.0" | - |
Affected
| in | Hpe Search vendor "Hpe" | Nimble Storage Af20 All Flash Array Search vendor "Hpe" for product "Nimble Storage Af20 All Flash Array" | - | - |
Safe
|
Hpe Search vendor "Hpe" | Nimbleos Search vendor "Hpe" for product "Nimbleos" | >= 4.1.0.0 <= 4.5.6.0 Search vendor "Hpe" for product "Nimbleos" and version " >= 4.1.0.0 <= 4.5.6.0" | - |
Affected
| in | Hpe Search vendor "Hpe" | Nimble Storage Af20q All Flash Dual Controller Search vendor "Hpe" for product "Nimble Storage Af20q All Flash Dual Controller" | - | - |
Safe
|
Hpe Search vendor "Hpe" | Nimbleos Search vendor "Hpe" for product "Nimbleos" | >= 4.1.0.0 <= 4.5.6.0 Search vendor "Hpe" for product "Nimbleos" and version " >= 4.1.0.0 <= 4.5.6.0" | - |
Affected
| in | Hpe Search vendor "Hpe" | Nimble Storage Af40 All Flash Dual Controller Search vendor "Hpe" for product "Nimble Storage Af40 All Flash Dual Controller" | - | - |
Safe
|
Hpe Search vendor "Hpe" | Nimbleos Search vendor "Hpe" for product "Nimbleos" | >= 4.1.0.0 <= 4.5.6.0 Search vendor "Hpe" for product "Nimbleos" and version " >= 4.1.0.0 <= 4.5.6.0" | - |
Affected
| in | Hpe Search vendor "Hpe" | Nimble Storage Af60 All Flash Dual Controller Search vendor "Hpe" for product "Nimble Storage Af60 All Flash Dual Controller" | - | - |
Safe
|
Hpe Search vendor "Hpe" | Nimbleos Search vendor "Hpe" for product "Nimbleos" | >= 4.1.0.0 <= 4.5.6.0 Search vendor "Hpe" for product "Nimbleos" and version " >= 4.1.0.0 <= 4.5.6.0" | - |
Affected
| in | Hpe Search vendor "Hpe" | Nimble Storage Af80 All Flash Dual Controller Search vendor "Hpe" for product "Nimble Storage Af80 All Flash Dual Controller" | - | - |
Safe
|
Hpe Search vendor "Hpe" | Nimbleos Search vendor "Hpe" for product "Nimbleos" | >= 4.1.0.0 <= 4.5.6.0 Search vendor "Hpe" for product "Nimbleos" and version " >= 4.1.0.0 <= 4.5.6.0" | - |
Affected
| in | Hpe Search vendor "Hpe" | Nimble Storage Cs3000 Search vendor "Hpe" for product "Nimble Storage Cs3000" | - | - |
Safe
|
Hpe Search vendor "Hpe" | Nimbleos Search vendor "Hpe" for product "Nimbleos" | >= 4.1.0.0 <= 4.5.6.0 Search vendor "Hpe" for product "Nimbleos" and version " >= 4.1.0.0 <= 4.5.6.0" | - |
Affected
| in | Hpe Search vendor "Hpe" | Nimble Storage Cs5000 Search vendor "Hpe" for product "Nimble Storage Cs5000" | - | - |
Safe
|
Hpe Search vendor "Hpe" | Nimbleos Search vendor "Hpe" for product "Nimbleos" | >= 4.1.0.0 <= 4.5.6.0 Search vendor "Hpe" for product "Nimbleos" and version " >= 4.1.0.0 <= 4.5.6.0" | - |
Affected
| in | Hpe Search vendor "Hpe" | Nimble Storage Cs7000 Search vendor "Hpe" for product "Nimble Storage Cs7000" | - | - |
Safe
|
Hpe Search vendor "Hpe" | Nimbleos Search vendor "Hpe" for product "Nimbleos" | >= 4.1.0.0 <= 4.5.6.0 Search vendor "Hpe" for product "Nimbleos" and version " >= 4.1.0.0 <= 4.5.6.0" | - |
Affected
| in | Hpe Search vendor "Hpe" | Nimble Storage Secondary Flash Arrays Search vendor "Hpe" for product "Nimble Storage Secondary Flash Arrays" | - | - |
Safe
|
Hpe Search vendor "Hpe" | Nimbleos Search vendor "Hpe" for product "Nimbleos" | >= 5.0.1.0 <= 5.0.9.0 Search vendor "Hpe" for product "Nimbleos" and version " >= 5.0.1.0 <= 5.0.9.0" | - |
Affected
| in | Hpe Search vendor "Hpe" | Nimble Storage Af20 All Flash Array Search vendor "Hpe" for product "Nimble Storage Af20 All Flash Array" | - | - |
Safe
|
Hpe Search vendor "Hpe" | Nimbleos Search vendor "Hpe" for product "Nimbleos" | >= 5.0.1.0 <= 5.0.9.0 Search vendor "Hpe" for product "Nimbleos" and version " >= 5.0.1.0 <= 5.0.9.0" | - |
Affected
| in | Hpe Search vendor "Hpe" | Nimble Storage Af20q All Flash Dual Controller Search vendor "Hpe" for product "Nimble Storage Af20q All Flash Dual Controller" | - | - |
Safe
|
Hpe Search vendor "Hpe" | Nimbleos Search vendor "Hpe" for product "Nimbleos" | >= 5.0.1.0 <= 5.0.9.0 Search vendor "Hpe" for product "Nimbleos" and version " >= 5.0.1.0 <= 5.0.9.0" | - |
Affected
| in | Hpe Search vendor "Hpe" | Nimble Storage Af40 All Flash Dual Controller Search vendor "Hpe" for product "Nimble Storage Af40 All Flash Dual Controller" | - | - |
Safe
|
Hpe Search vendor "Hpe" | Nimbleos Search vendor "Hpe" for product "Nimbleos" | >= 5.0.1.0 <= 5.0.9.0 Search vendor "Hpe" for product "Nimbleos" and version " >= 5.0.1.0 <= 5.0.9.0" | - |
Affected
| in | Hpe Search vendor "Hpe" | Nimble Storage Af60 All Flash Dual Controller Search vendor "Hpe" for product "Nimble Storage Af60 All Flash Dual Controller" | - | - |
Safe
|
Hpe Search vendor "Hpe" | Nimbleos Search vendor "Hpe" for product "Nimbleos" | >= 5.0.1.0 <= 5.0.9.0 Search vendor "Hpe" for product "Nimbleos" and version " >= 5.0.1.0 <= 5.0.9.0" | - |
Affected
| in | Hpe Search vendor "Hpe" | Nimble Storage Af80 All Flash Dual Controller Search vendor "Hpe" for product "Nimble Storage Af80 All Flash Dual Controller" | - | - |
Safe
|
Hpe Search vendor "Hpe" | Nimbleos Search vendor "Hpe" for product "Nimbleos" | >= 5.0.1.0 <= 5.0.9.0 Search vendor "Hpe" for product "Nimbleos" and version " >= 5.0.1.0 <= 5.0.9.0" | - |
Affected
| in | Hpe Search vendor "Hpe" | Nimble Storage Cs3000 Search vendor "Hpe" for product "Nimble Storage Cs3000" | - | - |
Safe
|
Hpe Search vendor "Hpe" | Nimbleos Search vendor "Hpe" for product "Nimbleos" | >= 5.0.1.0 <= 5.0.9.0 Search vendor "Hpe" for product "Nimbleos" and version " >= 5.0.1.0 <= 5.0.9.0" | - |
Affected
| in | Hpe Search vendor "Hpe" | Nimble Storage Cs5000 Search vendor "Hpe" for product "Nimble Storage Cs5000" | - | - |
Safe
|
Hpe Search vendor "Hpe" | Nimbleos Search vendor "Hpe" for product "Nimbleos" | >= 5.0.1.0 <= 5.0.9.0 Search vendor "Hpe" for product "Nimbleos" and version " >= 5.0.1.0 <= 5.0.9.0" | - |
Affected
| in | Hpe Search vendor "Hpe" | Nimble Storage Cs7000 Search vendor "Hpe" for product "Nimble Storage Cs7000" | - | - |
Safe
|
Hpe Search vendor "Hpe" | Nimbleos Search vendor "Hpe" for product "Nimbleos" | >= 5.0.1.0 <= 5.0.9.0 Search vendor "Hpe" for product "Nimbleos" and version " >= 5.0.1.0 <= 5.0.9.0" | - |
Affected
| in | Hpe Search vendor "Hpe" | Nimble Storage Secondary Flash Arrays Search vendor "Hpe" for product "Nimble Storage Secondary Flash Arrays" | - | - |
Safe
|
Hpe Search vendor "Hpe" | Nimbleos Search vendor "Hpe" for product "Nimbleos" | >= 5.1.0.0 <= 5.1.4.100 Search vendor "Hpe" for product "Nimbleos" and version " >= 5.1.0.0 <= 5.1.4.100" | - |
Affected
| in | Hpe Search vendor "Hpe" | Nimble Storage Af20 All Flash Array Search vendor "Hpe" for product "Nimble Storage Af20 All Flash Array" | - | - |
Safe
|
Hpe Search vendor "Hpe" | Nimbleos Search vendor "Hpe" for product "Nimbleos" | >= 5.1.0.0 <= 5.1.4.100 Search vendor "Hpe" for product "Nimbleos" and version " >= 5.1.0.0 <= 5.1.4.100" | - |
Affected
| in | Hpe Search vendor "Hpe" | Nimble Storage Af20q All Flash Dual Controller Search vendor "Hpe" for product "Nimble Storage Af20q All Flash Dual Controller" | - | - |
Safe
|
Hpe Search vendor "Hpe" | Nimbleos Search vendor "Hpe" for product "Nimbleos" | >= 5.1.0.0 <= 5.1.4.100 Search vendor "Hpe" for product "Nimbleos" and version " >= 5.1.0.0 <= 5.1.4.100" | - |
Affected
| in | Hpe Search vendor "Hpe" | Nimble Storage Af40 All Flash Dual Controller Search vendor "Hpe" for product "Nimble Storage Af40 All Flash Dual Controller" | - | - |
Safe
|
Hpe Search vendor "Hpe" | Nimbleos Search vendor "Hpe" for product "Nimbleos" | >= 5.1.0.0 <= 5.1.4.100 Search vendor "Hpe" for product "Nimbleos" and version " >= 5.1.0.0 <= 5.1.4.100" | - |
Affected
| in | Hpe Search vendor "Hpe" | Nimble Storage Af60 All Flash Dual Controller Search vendor "Hpe" for product "Nimble Storage Af60 All Flash Dual Controller" | - | - |
Safe
|
Hpe Search vendor "Hpe" | Nimbleos Search vendor "Hpe" for product "Nimbleos" | >= 5.1.0.0 <= 5.1.4.100 Search vendor "Hpe" for product "Nimbleos" and version " >= 5.1.0.0 <= 5.1.4.100" | - |
Affected
| in | Hpe Search vendor "Hpe" | Nimble Storage Af80 All Flash Dual Controller Search vendor "Hpe" for product "Nimble Storage Af80 All Flash Dual Controller" | - | - |
Safe
|
Hpe Search vendor "Hpe" | Nimbleos Search vendor "Hpe" for product "Nimbleos" | >= 5.1.0.0 <= 5.1.4.100 Search vendor "Hpe" for product "Nimbleos" and version " >= 5.1.0.0 <= 5.1.4.100" | - |
Affected
| in | Hpe Search vendor "Hpe" | Nimble Storage Cs3000 Search vendor "Hpe" for product "Nimble Storage Cs3000" | - | - |
Safe
|
Hpe Search vendor "Hpe" | Nimbleos Search vendor "Hpe" for product "Nimbleos" | >= 5.1.0.0 <= 5.1.4.100 Search vendor "Hpe" for product "Nimbleos" and version " >= 5.1.0.0 <= 5.1.4.100" | - |
Affected
| in | Hpe Search vendor "Hpe" | Nimble Storage Cs5000 Search vendor "Hpe" for product "Nimble Storage Cs5000" | - | - |
Safe
|
Hpe Search vendor "Hpe" | Nimbleos Search vendor "Hpe" for product "Nimbleos" | >= 5.1.0.0 <= 5.1.4.100 Search vendor "Hpe" for product "Nimbleos" and version " >= 5.1.0.0 <= 5.1.4.100" | - |
Affected
| in | Hpe Search vendor "Hpe" | Nimble Storage Cs7000 Search vendor "Hpe" for product "Nimble Storage Cs7000" | - | - |
Safe
|
Hpe Search vendor "Hpe" | Nimbleos Search vendor "Hpe" for product "Nimbleos" | >= 5.1.0.0 <= 5.1.4.100 Search vendor "Hpe" for product "Nimbleos" and version " >= 5.1.0.0 <= 5.1.4.100" | - |
Affected
| in | Hpe Search vendor "Hpe" | Nimble Storage Secondary Flash Arrays Search vendor "Hpe" for product "Nimble Storage Secondary Flash Arrays" | - | - |
Safe
|