CVE-2018-7108

MEDIUM

HPE StorageWorks XP7 Automation Director 8.5.2-02-8.6.1-00 - Authentication Bypass

Title source: llm
STIX 2.1

Description

HPE StorageWorks XP7 Automation Director (AutoDir) version 8.5.2-02 to earlier than 8.6.1-00 has a local and remote authentication bypass vulnerability that exposed the user authentication information of the storage system. This problem sometimes occurred under specific conditions when running a service template.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1041696

Scores

CVSS v3 5.9
EPSS 0.0107
EPSS Percentile 78.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-287
Status published
Products (1)
hpe/storageworks_xp7_automation_director 8.5.2-02 - 8.6.1-00
Published Sep 27, 2018
Tracked Since Feb 18, 2026