7.1

CVE-2019-12001

A remote session reuse vulnerability leading to access restriction bypass was discovered in HPE MSA 2040 SAN Storage; HPE MSA 1040 SAN Storage; HPE MSA 1050 SAN Storage; HPE MSA 2042 SAN Storage; HPE MSA 2050 SAN Storage; HPE MSA 2052 SAN Storage version(s): GL225P001 and earlier; GL225P001 and earlier; VE270R001-01 and earlier; GL225P001 and earlier; VL270R001-01 and earlier; VL270R001-01 and earlier.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HpeMsa 1040 Firmware Version <= gl225p001
   HpeMsa 1040 Version-
HpeMsa 2040 Firmware Version <= gl225p001
   HpeMsa 2040 Version-
HpeMsa 2042 Firmware Version <= gl225p001
   HpeMsa 2042 Version-
HpeMsa 1050 Firmware Version <= ve270r001-01
   HpeMsa 1050 Version-
HpeMsa 2050 Firmware Version <= vl270r001-01
   HpeMsa 2050 Version-
HpeMsa 2052 Firmware Version <= vl270r001-01
   HpeMsa 2052 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.11% 0.3
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.4 0.5 5.9
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 7.1 3.9 10
AV:N/AC:H/Au:S/C:C/I:C/A:C
CWE-613 Insufficient Session Expiration

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."