PT-2020-19457 · Hewlett Packard · Hpe 3Par Storeserv Management Console+1

Published

2020-10-25

·

Updated

2020-11-17

·

CVE-2020-7197

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HPE StoreServ Management Console (SSMC) version 3.7.0.0
Description The issue concerns a remote authentication bypass in HPE StoreServ Management Console (SSMC), which is an off-node multi-array manager web application. This application remains isolated from the data on the managed arrays.
Recommendations For HPE StoreServ Management Console (SSMC) version 3.7.0.0, upgrade to HPE 3PAR StoreServ Management Console 3.7.1.1 or later.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-7197

Affected Products

Hpe 3Par Storeserv Management Console
Hpe Storeserv Management Console