CVE-2022-37928

Severity CVSS v4.0:
Pending analysis
Type:
CWE-345 Insufficient Verification of Data Authenticity
Publication date:
12/12/2022
Last modified:
02/05/2025

Description

Insufficient Verification of Data Authenticity vulnerability in Hewlett Packard Enterprise HPE Nimble Storage Hybrid Flash Arrays and Nimble Storage Secondary Flash Arrays.<br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:hpe:sf100_firmware:*:*:*:*:ltsr:*:*:* 5.2.1.900 (excluding)
cpe:2.3:o:hpe:sf100_firmware:5.3.0.0:*:*:*:-:*:*:*
cpe:2.3:h:hpe:sf100:-:*:*:*:*:*:*:*
cpe:2.3:o:hpe:sf300_firmware:*:*:*:*:ltsr:*:*:* 5.2.1.900 (excluding)
cpe:2.3:o:hpe:sf300_firmware:5.3.0.0:*:*:*:-:*:*:*
cpe:2.3:h:hpe:sf300:-:*:*:*:*:*:*:*
cpe:2.3:o:hpe:hf60c_firmware:*:*:*:*:ltsr:*:*:* 5.2.1.900 (excluding)
cpe:2.3:o:hpe:hf60c_firmware:5.3.0.0:*:*:*:-:*:*:*
cpe:2.3:h:hpe:hf60c:-:*:*:*:*:*:*:*
cpe:2.3:o:hpe:hf40c_firmware:*:*:*:*:ltsr:*:*:* 5.2.1.900 (excluding)
cpe:2.3:o:hpe:hf40c_firmware:5.3.0.0:*:*:*:-:*:*:*
cpe:2.3:h:hpe:hf40c:-:*:*:*:*:*:*:*
cpe:2.3:o:hpe:hf20_firmware:*:*:*:*:ltsr:*:*:* 5.2.1.900 (excluding)
cpe:2.3:o:hpe:hf20_firmware:5.3.0.0:*:*:*:-:*:*:*
cpe:2.3:h:hpe:hf20:-:*:*:*:*:*:*:*