8.8

CVE-2020-7198

There is a remote escalation of privilege possible for a malicious user that has a OneView account in OneView and Synergy Composer. HPE has provided updates to Oneview and Synergy Composer: Update to version 5.5 of OneView, Composer, or Composer2.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HpOneview Version5.0
HpOneview Version5.00.01
HpOneview Version5.00.02
HpOneview Version5.2
HpOneview Version5.3
HpOneview Version5.4
HpOneview Version5.20.01
HpSynergy Composer Version5.0
HpSynergy Composer Version5.00.01
HpSynergy Composer Version5.00.02
HpSynergy Composer Version5.2
HpSynergy Composer Version5.3
HpSynergy Composer Version5.4
HpSynergy Composer Version5.20.01
HpSynergy Composer 2 Version5.0
HpSynergy Composer 2 Version5.00.01
HpSynergy Composer 2 Version5.00.02
HpSynergy Composer 2 Version5.2
HpSynergy Composer 2 Version5.3
HpSynergy Composer 2 Version5.4
HpSynergy Composer 2 Version5.20.01
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.39% 0.595
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P