Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-37928


Insufficient Verification of Data Authenticity vulnerability in Hewlett Packard Enterprise HPE Nimble Storage Hybrid Flash Arrays and Nimble Storage Secondary Flash Arrays.


Published

2022-12-12T13:15:14.173

Last Modified

2025-05-02T20:15:17.620

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.0 (HIGH)

Weaknesses
  • Type: Primary
    CWE-345
  • Type: Secondary
    CWE-345

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System hpe sf100_firmware < 5.2.1.900 Yes
Operating System hpe sf100_firmware 5.3.0.0 Yes
Hardware hpe sf100 - No
Operating System hpe sf300_firmware < 5.2.1.900 Yes
Operating System hpe sf300_firmware 5.3.0.0 Yes
Hardware hpe sf300 - No
Operating System hpe hf60c_firmware < 5.2.1.900 Yes
Operating System hpe hf60c_firmware 5.3.0.0 Yes
Hardware hpe hf60c - No
Operating System hpe hf40c_firmware < 5.2.1.900 Yes
Operating System hpe hf40c_firmware 5.3.0.0 Yes
Hardware hpe hf40c - No
Operating System hpe hf20_firmware < 5.2.1.900 Yes
Operating System hpe hf20_firmware 5.3.0.0 Yes
Hardware hpe hf20 - No
Operating System hpe hf40_firmware < 5.2.1.900 Yes
Operating System hpe hf40_firmware 5.3.0.0 Yes
Hardware hpe hf40 - No
Operating System hpe hf60_firmware < 5.2.1.900 Yes
Operating System hpe hf60_firmware 5.3.0.0 Yes
Hardware hpe hf60 - No
Operating System hpe hf20h_firmware < 5.2.1.900 Yes
Operating System hpe hf20h_firmware 5.3.0.0 Yes
Hardware hpe hf20h - No
Operating System hpe hf20c_firmware < 5.2.1.900 Yes
Operating System hpe hf20c_firmware 5.3.0.0 Yes
Hardware hpe hf20c - No

References