CVE-2020-7201
Severity CVSS v4.0:
Pending analysis
Type:
CWE-352
Cross-Site Request Forgery (CSRF)
Publication date:
18/12/2020
Last modified:
22/12/2020
Description
A potential security vulnerability has been identified in the HPE StoreEver MSL2024 Tape Library and HPE StoreEver 1/8 G2 Tape Autoloaders. The vulnerability could be remotely exploited to allow Cross-site Request Forgery (CSRF).
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:hp:storeever_msl2024_firmware:*:*:*:*:*:*:*:* | 7.30 (excluding) | |
| cpe:2.3:h:hp:storeever_msl2024:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:hp:storeever_1\/8_g2_tape_autoloader_firmware:*:*:*:*:*:*:*:* | 5.40 (excluding) | |
| cpe:2.3:h:hp:storeever_1\/8_g2_tape_autoloader:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



