// For flags

CVE-2021-26587

 

Severity Score

6.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A potential DOM-based Cross Site Scripting security vulnerability has been identified in HPE StoreOnce. The vulnerability could be remotely exploited to cause an elevation of privilege leading to partial impact to confidentiality, availability, and integrity. HPE has made the following software update - HPE StoreOnce 4.3.0, to resolve the vulnerability in HPE StoreOnce.

Se ha identificado una posible vulnerabilidad de seguridad de tipo Cross Site Scripting basada en DOM en HPE StoreOnce. La vulnerabilidad podría ser explotada remotamente para causar una elevación de privilegios que conlleva a un impacto parcial en la confidencialidad, la disponibilidad y la integridad. HPE ha realizado la siguiente actualización de software - HPE StoreOnce versión 4.3.0, para resolver la vulnerabilidad en HPE StoreOnce

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
Low
Attack Vector
Network
Attack Complexity
Medium
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-02-02 CVE Reserved
  • 2021-09-27 CVE Published
  • 2023-04-20 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Hpe
Search vendor "Hpe"
Storeonce 5200 Firmware
Search vendor "Hpe" for product "Storeonce 5200 Firmware"
<= 4.2.3
Search vendor "Hpe" for product "Storeonce 5200 Firmware" and version " <= 4.2.3"
-
Affected
in Hpe
Search vendor "Hpe"
Storeonce 5200
Search vendor "Hpe" for product "Storeonce 5200"
--
Safe
Hpe
Search vendor "Hpe"
Storeonce 5650 Firmware
Search vendor "Hpe" for product "Storeonce 5650 Firmware"
<= 4.2.3
Search vendor "Hpe" for product "Storeonce 5650 Firmware" and version " <= 4.2.3"
-
Affected
in Hpe
Search vendor "Hpe"
Storeonce 5650
Search vendor "Hpe" for product "Storeonce 5650"
--
Safe
Hpe
Search vendor "Hpe"
Storeonce 5250 Firmware
Search vendor "Hpe" for product "Storeonce 5250 Firmware"
<= 4.2.3
Search vendor "Hpe" for product "Storeonce 5250 Firmware" and version " <= 4.2.3"
-
Affected
in Hpe
Search vendor "Hpe"
Storeonce 5250
Search vendor "Hpe" for product "Storeonce 5250"
--
Safe
Hpe
Search vendor "Hpe"
Storeonce 3640 Firmware
Search vendor "Hpe" for product "Storeonce 3640 Firmware"
<= 4.2.3
Search vendor "Hpe" for product "Storeonce 3640 Firmware" and version " <= 4.2.3"
-
Affected
in Hpe
Search vendor "Hpe"
Storeonce 3640
Search vendor "Hpe" for product "Storeonce 3640"
--
Safe
Hpe
Search vendor "Hpe"
Storeonce 3620 Firmware
Search vendor "Hpe" for product "Storeonce 3620 Firmware"
<= 4.2.3
Search vendor "Hpe" for product "Storeonce 3620 Firmware" and version " <= 4.2.3"
-
Affected
in Hpe
Search vendor "Hpe"
Storeonce 3620
Search vendor "Hpe" for product "Storeonce 3620"
--
Safe
Hpe
Search vendor "Hpe"
Storeonce Vsa 4tb Firmware
Search vendor "Hpe" for product "Storeonce Vsa 4tb Firmware"
<= 4.2.3
Search vendor "Hpe" for product "Storeonce Vsa 4tb Firmware" and version " <= 4.2.3"
-
Affected
in Hpe
Search vendor "Hpe"
Storeonce Vsa 4tb
Search vendor "Hpe" for product "Storeonce Vsa 4tb"
--
Safe