CVE-2019-12002: Critical severity hpe msa 1040 san storage firmware vulnerability
A remote session reuse vulnerability leading to access restriction bypass was discovered in HPE MSA 2040 SAN Storage; HPE MSA 1040 SAN Storage; HPE MSA 1050 SAN Storage; HPE MSA 2042 SAN Storage; HPE MSA 2050 SAN Storage; HPE MSA 2052 SAN Storage version(s): GL225P001 and earlier; GL225P001 and earlier; VE270R001-01 and earlier; GL225P001 and earlier; VL270R001-01 and earlier; VL270R001-01 and earlier.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-12002?
CVE-2019-12002 is rated as a high-severity vulnerability due to its potential for remote session reuse and access restriction bypass.
How do I fix CVE-2019-12002?
To mitigate CVE-2019-12002, upgrade to firmware version GL225P002 or later for affected HPE MSA Storage models.
Which HPE models are affected by CVE-2019-12002?
CVE-2019-12002 affects HPE MSA 1040, 1050, 2040, 2042, 2050, and 2052 models running specific firmware versions.
What is the impact of CVE-2019-12002?
The impact of CVE-2019-12002 includes the risk of unauthorized access to sensitive data due to session reuse.
Is CVE-2019-12002 exploitable remotely?
Yes, CVE-2019-12002 can be exploited remotely, allowing attackers to bypass access restrictions.