SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-26587

A potential DOM-based Cross Site Scripting security vulnerability has been identified in HPE StoreOnce.

MEDIUM 6.5EPSS 0.50%

Does this matter?

Lower severity and a low EPSS score (0.50%). Track it; it rarely justifies an emergency change on its own.

Description

A potential DOM-based Cross Site Scripting security vulnerability has been identified in HPE StoreOnce. The vulnerability could be remotely exploited to cause an elevation of privilege leading to partial impact to confidentiality, availability, and integrity. HPE has made the following software update - HPE StoreOnce 4.3.0, to resolve the vulnerability in HPE StoreOnce.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
EPSS
0.50% probability · 41th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
hpe/storeonce 5200 firmware · hpe/storeonce 5650 firmware · hpe/storeonce 5250 firmware · hpe/storeonce 3640 firmware · hpe/storeonce 3620 firmware · hpe/storeonce vsa 4tb firmware
Source
security-alert@hpe.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.