CVE-2022-37940

MEDIUM

HPE FlexFabric 5700 Switch Series < R2432P61 - URL Redirection via Host Header Injection

Title source: llm
STIX 2.1

Description

Potential security vulnerabilities have been identified in the HPE FlexFabric 5700 Switch Series. These vulnerabilities could be remotely exploited to allow host header injection and URL redirection. HPE has made the following software to resolve the vulnerability in HPE FlexFabric 5700 Switch Series version R2432P61 or later.

Scores

CVSS v3 5.3
EPSS 0.0020
EPSS Percentile 42.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-601
Status published
Products (2)
hpe/flexfabric_5700_40xg_2qsfp\+_firmware < r2432p61
hpe/flexfabric_5700_48g_4xg_2qsfp\+_firmware < r2432p61
Published Mar 22, 2023
Tracked Since Feb 18, 2026