SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-5408

Command View Advanced Edition (CVAE) products contain a vulnerability that could expose configuration information of hosts and storage systems that are managed by Device Manager server.

MEDIUM 6.5EPSS 1.56%

Does this matter?

Lower severity and a low EPSS score (1.56%). Track it; it rarely justifies an emergency change on its own.

Description

Command View Advanced Edition (CVAE) products contain a vulnerability that could expose configuration information of hosts and storage systems that are managed by Device Manager server. This problem is due to a vulnerability in Device Manager GUI. The following products are affected. DevMgr version 7.0.0-00 to earlier than 8.6.1-02 RepMgr if it is installed on the same machine as DevMgr TSMgr if it is installed on the same machine as DevMgr. The resolution is to upgrade to the fixed version as described below or later version of DevMgr 8.6.2-02 or later. RepMgr and TSMgr will be corrected by upgrading DevMgr.

CVSS 3.0
6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS
1.56% probability · 74th percentile
CISA KEV
Not listed
Affected
hp/xp7 device manager · hp/xp7 replication manager · hp/xp7 tiered storage manager
Source
security-alert@hpe.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.