8.8

CVE-2020-7198

There is a remote escalation of privilege possible for a malicious user that has a OneView account in OneView and Synergy Composer. HPE has provided updates to Oneview and Synergy Composer: Update to version 5.5 of OneView, Composer, or Composer2.

Data is provided by the National Vulnerability Database (NVD)
HpOneview Version5.0
HpOneview Version5.00.01
HpOneview Version5.00.02
HpOneview Version5.2
HpOneview Version5.3
HpOneview Version5.4
HpOneview Version5.20.01
HpSynergy Composer Version5.0
HpSynergy Composer Version5.00.01
HpSynergy Composer Version5.00.02
HpSynergy Composer Version5.2
HpSynergy Composer Version5.3
HpSynergy Composer Version5.4
HpSynergy Composer Version5.20.01
HpSynergy Composer 2 Version5.0
HpSynergy Composer 2 Version5.00.01
HpSynergy Composer 2 Version5.00.02
HpSynergy Composer 2 Version5.2
HpSynergy Composer 2 Version5.3
HpSynergy Composer 2 Version5.4
HpSynergy Composer 2 Version5.20.01
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.39% 0.595
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P