Vulnerability Details CVE-2020-7138
Potential remote code execution security vulnerabilities have been identified with HPE Nimble Storage systems that could be exploited by an attacker to gain elevated privileges on the array. The following NimbleOS versions, and all subsequent releases, contain a software fix for this vulnerability: 3.9.3.0 4.5.6.0 5.0.9.0 5.1.4.100
Exploit prediction scoring system (EPSS) score
EPSS Score 0.019
EPSS Ranking 82.5%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.5
Products affected by CVE-2020-7138
-
cpe:2.3:h:hpe:nimble_storage_af20_all_flash_array:-
-
cpe:2.3:h:hpe:nimble_storage_af20q_all_flash_dual_controller:-
-
cpe:2.3:h:hpe:nimble_storage_af40_all_flash_dual_controller:-
-
cpe:2.3:h:hpe:nimble_storage_af60_all_flash_dual_controller:-
-
cpe:2.3:h:hpe:nimble_storage_af80_all_flash_dual_controller:-
-
cpe:2.3:h:hpe:nimble_storage_cs3000:-
-
cpe:2.3:h:hpe:nimble_storage_cs5000:-
-
cpe:2.3:h:hpe:nimble_storage_cs7000:-
-
cpe:2.3:h:hpe:nimble_storage_secondary_flash_arrays:-
-
cpe:2.3:o:hpe:nimbleos:3.1.0.0
-
cpe:2.3:o:hpe:nimbleos:3.2.1.0
-
cpe:2.3:o:hpe:nimbleos:3.3.0.0
-
cpe:2.3:o:hpe:nimbleos:3.4.0.0
-
cpe:2.3:o:hpe:nimbleos:3.4.1.0
-
cpe:2.3:o:hpe:nimbleos:3.5.0.0
-
cpe:2.3:o:hpe:nimbleos:3.5.2.0
-
cpe:2.3:o:hpe:nimbleos:3.5.3.0
-
cpe:2.3:o:hpe:nimbleos:3.5.4.0
-
cpe:2.3:o:hpe:nimbleos:3.6.0.0
-
cpe:2.3:o:hpe:nimbleos:3.6.1.0
-
cpe:2.3:o:hpe:nimbleos:3.6.2.0
-
cpe:2.3:o:hpe:nimbleos:3.7.0.0
-
cpe:2.3:o:hpe:nimbleos:3.8.0.0
-
cpe:2.3:o:hpe:nimbleos:3.8.1.0
-
cpe:2.3:o:hpe:nimbleos:3.9.0.0
-
cpe:2.3:o:hpe:nimbleos:3.9.1.0
-
cpe:2.3:o:hpe:nimbleos:3.9.2.0
-
cpe:2.3:o:hpe:nimbleos:3.9.3.0
-
cpe:2.3:o:hpe:nimbleos:4.1.0.0
-
cpe:2.3:o:hpe:nimbleos:4.2.0.0
-
cpe:2.3:o:hpe:nimbleos:4.2.1.0
-
cpe:2.3:o:hpe:nimbleos:4.3.0.0
-
cpe:2.3:o:hpe:nimbleos:4.3.1.0
-
cpe:2.3:o:hpe:nimbleos:4.4.0.0
-
cpe:2.3:o:hpe:nimbleos:4.4.1.0
-
cpe:2.3:o:hpe:nimbleos:4.5.0.0
-
cpe:2.3:o:hpe:nimbleos:4.5.1.0
-
cpe:2.3:o:hpe:nimbleos:4.5.2.0
-
cpe:2.3:o:hpe:nimbleos:4.5.3.0
-
cpe:2.3:o:hpe:nimbleos:4.5.4.0
-
cpe:2.3:o:hpe:nimbleos:4.5.5.0
-
cpe:2.3:o:hpe:nimbleos:4.5.6.0
-
cpe:2.3:o:hpe:nimbleos:5.0.1.0
-
cpe:2.3:o:hpe:nimbleos:5.0.1.0.100
-
cpe:2.3:o:hpe:nimbleos:5.0.1.100
-
cpe:2.3:o:hpe:nimbleos:5.0.2.0
-
cpe:2.3:o:hpe:nimbleos:5.0.3.0
-
cpe:2.3:o:hpe:nimbleos:5.0.3.100
-
cpe:2.3:o:hpe:nimbleos:5.0.4.0
-
cpe:2.3:o:hpe:nimbleos:5.0.5.0
-
cpe:2.3:o:hpe:nimbleos:5.0.5.200
-
cpe:2.3:o:hpe:nimbleos:5.0.6.0
-
cpe:2.3:o:hpe:nimbleos:5.0.7.0
-
cpe:2.3:o:hpe:nimbleos:5.0.7.300
-
cpe:2.3:o:hpe:nimbleos:5.0.8.0
-
cpe:2.3:o:hpe:nimbleos:5.0.9.0
-
cpe:2.3:o:hpe:nimbleos:5.1.0.0
-
cpe:2.3:o:hpe:nimbleos:5.1.1.0
-
cpe:2.3:o:hpe:nimbleos:5.1.2.0
-
cpe:2.3:o:hpe:nimbleos:5.1.2.100
-
cpe:2.3:o:hpe:nimbleos:5.1.3.0
-
cpe:2.3:o:hpe:nimbleos:5.1.3.100
-
cpe:2.3:o:hpe:nimbleos:5.1.4.0
-
cpe:2.3:o:hpe:nimbleos:5.1.4.100