CVE-2017-8959: High severity hpe msa 1040 san storage firmware vulnerability
Published Feb 15, 2018
·Updated
An Authentication Bypass vulnerability in HPE MSA 1040 and HPE MSA 2040 SAN Storage in version GL220P008 and earlier and was found.
Affected Software
4 affected components
HP Msa 1040 San Storage Firmware<=gl220p008
HP Msa 1040 San Storage
HP Msa 2040 San Storage Firmware<=gl220p008
HP MSA 2040 SAN Storage
Event History
Feb 15, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-8959?
CVE-2017-8959 has been classified with a critical severity rating due to its potential for authentication bypass.
2
How do I fix CVE-2017-8959?
To mitigate CVE-2017-8959, upgrade the HPE MSA 1040 or HPE MSA 2040 SAN Storage Firmware to a version later than GL220P008.
3
Which products are affected by CVE-2017-8959?
CVE-2017-8959 affects HPE MSA 1040 and HPE MSA 2040 SAN Storage systems running GL220P008 or earlier.
4
What is the impact of CVE-2017-8959?
The impact of CVE-2017-8959 is that unauthorized users may gain access to sensitive storage resources.
5
Is my HPE MSA 1040 or HPE MSA 2040 vulnerable if it is updated?
If your HPE MSA 1040 or HPE MSA 2040 has been updated to a firmware version after GL220P008, it is not vulnerable to CVE-2017-8959.