CVE-2020-7201

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
18/12/2020
Last modified:
22/12/2020

Description

A potential security vulnerability has been identified in the HPE StoreEver MSL2024 Tape Library and HPE StoreEver 1/8 G2 Tape Autoloaders. The vulnerability could be remotely exploited to allow Cross-site Request Forgery (CSRF).

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:hp:storeever_msl2024_firmware:*:*:*:*:*:*:*:* 7.30 (excluding)
cpe:2.3:h:hp:storeever_msl2024:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:storeever_1\/8_g2_tape_autoloader_firmware:*:*:*:*:*:*:*:* 5.40 (excluding)
cpe:2.3:h:hp:storeever_1\/8_g2_tape_autoloader:-:*:*:*:*:*:*:*