CVE-2019-11991

CRITICAL

HPE 3PAR Service Processor Firmware 4.1-4.4 - Remote Information Disclosure

Title source: llm
STIX 2.1

Description

HPE has identified a vulnerability in HPE 3PAR Service Processor (SP) version 4.1 through 4.4. HPE 3PAR Service Processor (SP) version 4.1 through 4.4 has a remote information disclosure vulnerability which can allow for the disruption of the confidentiality, integrity and availability of the Service Processor and any managed 3PAR arrays.

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.0291
EPSS Percentile 86.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-200
Status published
Products (1)
hp/3par_service_processor_firmware 4.1 - 4.4
Published Jul 09, 2019
Tracked Since Feb 18, 2026