Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-26588


A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 Storage array firmware. An unauthenticated user could remotely exploit the low complexity issue to execute code as administrator. This vulnerability impacts completely the confidentiality, integrity, availability of the array. HPE has made the following software updates and mitigation information to resolve the vulnerability in 3PAR, Primera and Alletra 9000 firmware.


Published

2021-10-11T17:15:07.637

Last Modified

2024-11-21T05:56:32.380

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System hpe 3par_os 3.3.1_mp5_p156 Yes
Operating System hpe 3par_os 3.3.1_mu1 Yes
Operating System hpe 3par_os 3.3.1_mu2_p157 Yes
Operating System hpe 3par_os 3.3.2_ga_p_01 Yes
Hardware hpe 3par_storeserv_10400 - No
Hardware hpe 3par_storeserv_10800 - No
Hardware hpe 3par_storeserv_20000 - No
Hardware hpe 3par_storeserv_7200c - No
Hardware hpe 3par_storeserv_7400c - No
Hardware hpe 3par_storeserv_7440c - No
Hardware hpe 3par_storeserv_8000 - No
Hardware hpe 3par_storeserv_9000 - No
Operating System hpe primera_630_firmware ≤ 4.3.3 Yes
Hardware hpe primera_630 - No
Operating System hpe primera_650_firmware ≤ 4.3.3 Yes
Hardware hpe primera_650 - No
Operating System hpe primera_670_firmware ≤ 4.3.3 Yes
Hardware hpe primera_670 - No
Operating System hpe alletra_9060_firmware ≤ 9.4.0 Yes
Hardware hpe alletra_9060 - No
Operating System hpe alletra_9080_firmware ≤ 9.4.0 Yes
Hardware hpe alletra_9080 - No

References