CVE-2019-11996: Critical severity hpe nimble storage vulnerability
Potential security vulnerabilities have been identified with HPE Nimble Storage systems in multi array group configurations. The vulnerabilities could be exploited by an attacker to gain elevated privileges on the array. The following NimbleOS versions, and all subsequent releases, contain a software fix for this vulnerability: 3.9.2.0, 4.5.5.0, 5.0.8.0 and 5.1.3.0.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of the HPE Nimble Storage vulnerability?
The vulnerability ID of the HPE Nimble Storage vulnerability is CVE-2019-11996.
What is the severity of CVE-2019-11996?
The severity of CVE-2019-11996 is critical, with a score of 9.8 out of 10.
Which HPE Nimble Storage systems are affected by CVE-2019-11996?
HPE Nimble Storage systems running NimbleOS versions 3.1.0.0 to 3.9.1.0, 4.1.0.0 to 4.5.4.0, 5.0.1.0 to 5.0.7.0, and 5.1.0.0 to 5.1.2.0 are affected by CVE-2019-11996.
What can an attacker do with CVE-2019-11996?
An attacker exploiting CVE-2019-11996 can gain elevated privileges on the HPE Nimble Storage array.
How can I fix the CVE-2019-11996 vulnerability?
To fix the CVE-2019-11996 vulnerability, upgrade to a version of NimbleOS that is not affected by the vulnerability as mentioned in the HPE advisory.