Vulnerabilities > HPE > Nimbleos > High

DATE CVE VULNERABILITY TITLE RISK
2022-05-20 CVE-2022-28618 Command Injection vulnerability in HPE Nimbleos
A command injection security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays and HPE Nimble Storage Secondary Flash Arrays that could allow an attacker to execute arbitrary commands on a Nimble appliance.
network
low complexity
hpe CWE-77
7.5
2022-05-09 CVE-2022-23705 Unspecified vulnerability in HPE Nimbleos
A security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays, and HPE Nimble Storage Secondary Flash Arrays which could potentially allow the upload, but not execution, of unauthorized update binaries to the array.
network
low complexity
hpe
7.5