CVE-2021-26588

A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 Storage array firmware. An unauthenticated user could remotely exploit the low complexity issue to execute code as administrator. This vulnerability impacts completely the confidentiality, integrity, availability of the array. HPE has made the following software updates and mitigation information to resolve the vulnerability in 3PAR, Primera and Alletra 9000 firmware.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:hpe:3par_os:3.3.1_mp5_p156:*:*:*:*:*:*:*
cpe:2.3:o:hpe:3par_os:3.3.1_mu1:*:*:*:*:*:*:*
cpe:2.3:o:hpe:3par_os:3.3.1_mu2_p157:*:*:*:*:*:*:*
cpe:2.3:o:hpe:3par_os:3.3.2_ga_p_01:*:*:*:*:*:*:*
OR cpe:2.3:h:hpe:3par_storeserv_10400:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:3par_storeserv_10800:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:3par_storeserv_20000:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:3par_storeserv_7200c:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:3par_storeserv_7400c:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:3par_storeserv_7440c:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:3par_storeserv_8000:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:3par_storeserv_9000:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:hpe:primera_630_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hpe:primera_630:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:hpe:primera_650_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hpe:primera_650:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:hpe:primera_670_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hpe:primera_670:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:hpe:alletra_9060_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hpe:alletra_9060:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:hpe:alletra_9080_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hpe:alletra_9080:-:*:*:*:*:*:*:*

History

18 Oct 2021, 17:52

Type Values Removed Values Added
References (MISC) https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst04191en_us - (MISC) https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst04191en_us - Vendor Advisory
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : 10.0
v3 : 9.8
CPE cpe:2.3:h:hpe:3par_storeserv_7440c:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:alletra_9060:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:3par_storeserv_8000:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:3par_storeserv_9000:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:3par_storeserv_10400:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:primera_670:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:3par_storeserv_7200c:-:*:*:*:*:*:*:*
cpe:2.3:o:hpe:primera_630_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:hpe:3par_os:3.3.2_ga_p_01:*:*:*:*:*:*:*
cpe:2.3:o:hpe:alletra_9080_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:hpe:3par_os:3.3.1_mu1:*:*:*:*:*:*:*
cpe:2.3:h:hpe:primera_650:-:*:*:*:*:*:*:*
cpe:2.3:o:hpe:primera_670_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:hpe:primera_650_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hpe:alletra_9080:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:3par_storeserv_7400c:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:primera_630:-:*:*:*:*:*:*:*
cpe:2.3:o:hpe:3par_os:3.3.1_mp5_p156:*:*:*:*:*:*:*
cpe:2.3:h:hpe:3par_storeserv_20000:-:*:*:*:*:*:*:*
cpe:2.3:o:hpe:alletra_9060_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:hpe:3par_os:3.3.1_mu2_p157:*:*:*:*:*:*:*
cpe:2.3:h:hpe:3par_storeserv_10800:-:*:*:*:*:*:*:*

11 Oct 2021, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-10-11 17:15

Updated : 2023-12-10 14:09


NVD link : CVE-2021-26588

Mitre link : CVE-2021-26588

CVE.ORG link : CVE-2021-26588


JSON object : View

Products Affected

hpe

  • primera_670
  • 3par_storeserv_10800
  • alletra_9060
  • 3par_storeserv_7400c
  • alletra_9080_firmware
  • primera_650
  • 3par_storeserv_7200c
  • 3par_os
  • 3par_storeserv_9000
  • primera_630
  • primera_630_firmware
  • alletra_9060_firmware
  • 3par_storeserv_20000
  • alletra_9080
  • primera_670_firmware
  • primera_650_firmware
  • 3par_storeserv_7440c
  • 3par_storeserv_10400
  • 3par_storeserv_8000