CVE-2022-37930
MEDIUMHPE Nimble Storage Hybrid Flash Arrays and Secondary Flash Arrays < 5.2.1.900 - Local Sensitive Information Exposure
Title source: llmDescription
A security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays and HPE Nimble Storage Secondary Flash Arrays which could potentially allow local disclosure of sensitive information.
References (1)
Core 1
Core References
Scores
CVSS v3
6.7
EPSS
0.0004
EPSS Percentile
13.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-200
Status
published
Products (18)
hpe/hf20_firmware
5.3.0.0
hpe/hf20_firmware
< 5.2.1.900
hpe/hf20c_firmware
5.3.0.0
hpe/hf20c_firmware
< 5.2.1.900
hpe/hf20h_firmware
5.3.0.0
hpe/hf20h_firmware
< 5.2.1.900
hpe/hf40_firmware
5.3.0.0
hpe/hf40_firmware
< 5.2.1.900
hpe/hf40c_firmware
5.3.0.0
hpe/hf40c_firmware
< 5.2.1.900
... and 8 more
Published
Dec 12, 2022
Tracked Since
Feb 18, 2026