cvelist/2022/37xxx/CVE-2022-37940.json

87 lines
2.9 KiB
JSON
Raw Normal View History

2022-08-08 19:01:02 +00:00
{
2023-03-22 06:00:39 +00:00
"data_version": "4.0",
2022-08-08 19:01:02 +00:00
"data_type": "CVE",
"data_format": "MITRE",
"CVE_data_meta": {
"ID": "CVE-2022-37940",
2023-03-22 06:00:39 +00:00
"ASSIGNER": "security-alert@hpe.com",
"STATE": "PUBLIC"
2022-08-08 19:01:02 +00:00
},
"description": {
"description_data": [
{
"lang": "eng",
2023-03-22 06:00:39 +00:00
"value": "Potential security vulnerabilities have been identified in the HPE FlexFabric 5700 Switch Series. These vulnerabilities could be remotely exploited to allow host header injection and URL redirection. HPE has made the following software to resolve the vulnerability in HPE FlexFabric 5700 Switch Series version R2432P61 or later."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "Hewlett Packard Enterprise (HPE)",
"product": {
"product_data": [
{
"product_name": "HPE FlexFabric 5700 Switch Series",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "Prior to R2432P61"
}
]
}
}
]
}
}
]
}
},
"references": {
"reference_data": [
{
"url": "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbnw04398en_us",
"refsource": "MISC",
"name": "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbnw04398en_us"
}
]
},
"generator": {
"engine": "cveClient/1.0.13"
},
"source": {
"discovery": "UNKNOWN"
},
"impact": {
"cvss": [
{
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
2022-08-08 19:01:02 +00:00
}
]
}
}