VulnerabilityModified
CVE-2021-26587
A potential DOM-based Cross Site Scripting security vulnerability has been identified in HPE StoreOnce.
MEDIUM 6.5EPSS 0.50%
Does this matter?
Lower severity and a low EPSS score (0.50%). Track it; it rarely justifies an emergency change on its own.
Description
A potential DOM-based Cross Site Scripting security vulnerability has been identified in HPE StoreOnce. The vulnerability could be remotely exploited to cause an elevation of privilege leading to partial impact to confidentiality, availability, and integrity. HPE has made the following software update - HPE StoreOnce 4.3.0, to resolve the vulnerability in HPE StoreOnce.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
- EPSS
- 0.50% probability · 41th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- hpe/storeonce 5200 firmware · hpe/storeonce 5650 firmware · hpe/storeonce 5250 firmware · hpe/storeonce 3640 firmware · hpe/storeonce 3620 firmware · hpe/storeonce vsa 4tb firmware
- Source
- security-alert@hpe.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.