PT-2020-19457 · Hewlett Packard · Hpe 3Par Storeserv Management Console+1
Published
2020-10-25
·
Updated
2020-11-17
·
CVE-2020-7197
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
HPE StoreServ Management Console (SSMC) version 3.7.0.0
Description
The issue concerns a remote authentication bypass in HPE StoreServ Management Console (SSMC), which is an off-node multi-array manager web application. This application remains isolated from the data on the managed arrays.
Recommendations
For HPE StoreServ Management Console (SSMC) version 3.7.0.0, upgrade to HPE 3PAR StoreServ Management Console 3.7.1.1 or later.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hpe 3Par Storeserv Management Console
Hpe Storeserv Management Console