CVE-2022-28622

HIGH

HPE StoreOnce Software <4.3.2 - RCE

Title source: llm
STIX 2.1

Description

A potential security vulnerability has been identified in HPE StoreOnce Software. The SSH server supports weak key exchange algorithms which could lead to remote unauthorized access. HPE has made the following software update to resolve the vulnerability in HPE StoreOnce Software 4.3.2.

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.0026
EPSS Percentile 49.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-327
Status published
Products (1)
hpe/storeonce_3640_firmware < 4.3.2
Published Jun 27, 2022
Tracked Since Feb 18, 2026