CVE-2019-11996

CRITICAL

HPE Nimble Storage - Privilege Escalation

Title source: llm
STIX 2.1

Description

Potential security vulnerabilities have been identified with HPE Nimble Storage systems in multi array group configurations. The vulnerabilities could be exploited by an attacker to gain elevated privileges on the array. The following NimbleOS versions, and all subsequent releases, contain a software fix for this vulnerability: 3.9.2.0, 4.5.5.0, 5.0.8.0 and 5.1.3.0.

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.0044
EPSS Percentile 63.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (1)
hpe/nimbleos 3.1.0.0 - 3.9.1.0
Published Nov 07, 2019
Tracked Since Feb 18, 2026