CVE-2019-12001: High severity hpe msa 1040 san storage firmware vulnerability
A remote session reuse vulnerability leading to access restriction bypass was discovered in HPE MSA 2040 SAN Storage; HPE MSA 1040 SAN Storage; HPE MSA 1050 SAN Storage; HPE MSA 2042 SAN Storage; HPE MSA 2050 SAN Storage; HPE MSA 2052 SAN Storage version(s): GL225P001 and earlier; GL225P001 and earlier; VE270R001-01 and earlier; GL225P001 and earlier; VL270R001-01 and earlier; VL270R001-01 and earlier.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-12001?
CVE-2019-12001 has been classified as a medium severity vulnerability.
How do I fix CVE-2019-12001?
To mitigate CVE-2019-12001, upgrade to firmware versions newer than GL225P001 for HPE MSA 1040, 2040, 1050, 2042, 2050, and 2052.
Which devices are affected by CVE-2019-12001?
CVE-2019-12001 affects HPE MSA 1040, 2040, 1050, 2042, 2050, and 2052 SAN Storage with specific firmware versions.
Can CVE-2019-12001 be exploited remotely?
Yes, CVE-2019-12001 allows for remote session reuse, potentially enabling unauthorized access.
Is there a known workaround for CVE-2019-12001?
There are no specific workarounds for CVE-2019-12001; updating to a secure firmware version is necessary.