9.8
CVE-2019-11991
- EPSS 2.91%
- Veröffentlicht 09.07.2019 19:15:12
- Zuletzt bearbeitet 21.11.2024 04:22:07
- Quelle security-alert@hpe.com
- Teams Watchlist Login
- Unerledigt Login
HPE has identified a vulnerability in HPE 3PAR Service Processor (SP) version 4.1 through 4.4. HPE 3PAR Service Processor (SP) version 4.1 through 4.4 has a remote information disclosure vulnerability which can allow for the disruption of the confidentiality, integrity and availability of the Service Processor and any managed 3PAR arrays.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hp ≫ 3par Service Processor Firmware Version >= 4.1 <= 4.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 2.91% | 0.851 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 9.7 | 10 | 9.5 |
AV:N/AC:L/Au:N/C:P/I:C/A:C
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.