First published: Fri Jun 24 2022(Updated: )
A remote authentication bypass vulnerability was discovered in HPE Cray Legacy Shasta System Solutions; HPE Slingshot; and HPE Cray EX supercomputers versions: Prior to node controller firmware associated with HPE Cray EX liquid cooled blades, and all versions of chassis controller firmware associated with HPE Cray EX liquid cooled cabinets prior to 1.6.27/1.5.33/1.4.27; All Slingshot versions prior to 1.7.2; All versions of node controller firmware associated with HPE Cray EX liquid cooled blades, and all versions of chassis controller firmware associated with HPE Cray EX liquid cooled cabinets prior to 1.6.27/1.5.33/1.4.27. HPE has provided a software update to resolve this vulnerability in HPE Cray Legacy Shasta System Solutions, HPE Slingshot, and HPE Cray EX Supercomputers.
Credit: security-alert@hpe.com security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hpe Slingshot Firmware | <1.7.2 | |
HPE Slingshot | ||
Hpe Cray Ex Supercomputers Firmware | =1.4.27 | |
Hpe Cray Ex Supercomputers Firmware | =1.5.33 | |
Hpe Cray Ex Supercomputers Firmware | =1.6.27 | |
HPE Cray EX supercomputers | ||
Hpe Cray Sh Supercomputer Air Cooled Base System Code Firmware | =1.4.27 | |
Hpe Cray Sh Supercomputer Air Cooled Base System Code Firmware | =1.5.33 | |
Hpe Cray Sh Supercomputer Air Cooled Base System Code Firmware | =1.6.27 | |
Hpe Cray Sh Supercomputer Air Cooled Base System Code | ||
Hpe Cray Sh Supercomputer Liquid Cooled Base System Code Firmware | =1.4.27 | |
Hpe Cray Sh Supercomputer Liquid Cooled Base System Code Firmware | =1.5.33 | |
Hpe Cray Sh Supercomputer Liquid Cooled Base System Code Firmware | =1.6.27 | |
Hpe Cray Sh Supercomputer Liquid Cooled Base System Code | ||
Hpe Cray Sh Supercomputer Liquid Cooled Tds Base System Code Firmware | =1.4.27 | |
Hpe Cray Sh Supercomputer Liquid Cooled Tds Base System Code Firmware | =1.5.33 | |
Hpe Cray Sh Supercomputer Liquid Cooled Tds Base System Code Firmware | =1.6.27 | |
Hpe Cray Sh Supercomputer Liquid Cooled Tds Base System Code |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-28620 is critical with a severity value of 9.8.
The affected software versions include HPE Slingshot Firmware up to version 1.7.2 and all versions of chassis controller firmware associated with HPE Cray EX supercomputers.
To fix CVE-2022-28620, update the affected software to the latest version provided by HPE.
You can find more information about CVE-2022-28620 on the HPE support website.