« Volver al listado

CVE-2020-7198

Estado: ModificadaAlta (8.8)—

There is a remote escalation of privilege possible for a malicious user that has a OneView account in OneView and Synergy Composer. HPE has provided updates to Oneview and Synergy Composer: Update to version 5.5 of OneView, Composer, or Composer2.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-7198",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-alert@hpe.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "HP OneView; HPE Synergy Composer; HPE Synergy Composer 2",
          "versions": [
            {
              "status": "affected",
              "version": "5.0, 5.00.01, 5.00.02, 5.2, 5.20.01, 5.3, 5.4"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-11-06T15:15:12.097",
  "references": [
    {
      "url": "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf04047en_us",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security-alert@hpe.com"
    },
    {
      "url": "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf04047en_us",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "There is a remote escalation of privilege possible for a malicious user that has a OneView account in OneView and Synergy Composer. HPE has provided updates to Oneview and Synergy Composer: Update to version 5.5 of OneView, Composer, or Composer2."
    },
    {
      "lang": "es",
      "value": "Se presenta una posible escalada de privilegios remota para un usuario malicioso que posee una cuenta de OneView en OneView y Synergy Composer. HPE ha proporcionado actualizaciones para Oneview y Synergy Composer: Actualice a la versión 5.5 de OneView, Composer o Composer2"
    }
  ],
  "lastModified": "2026-06-17T03:24:29.487",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:hp:oneview:5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7B43798D-E077-4DCC-B360-495F3260566B"
            },
            {
              "criteria": "cpe:2.3:a:hp:oneview:5.00.01:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "413D7888-B5F5-41D3-BBD8-E3821ED5AF03"
            },
            {
              "criteria": "cpe:2.3:a:hp:oneview:5.00.02:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "57CA44FC-88D3-434C-AAF4-29B77946CE46"
            },
            {
              "criteria": "cpe:2.3:a:hp:oneview:5.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0C164845-25B5-4492-BBCC-4504D5B7EF98"
            },
            {
              "criteria": "cpe:2.3:a:hp:oneview:5.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7FF30AB6-5577-4E02-86DD-8A4B984C0254"
            },
            {
              "criteria": "cpe:2.3:a:hp:oneview:5.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "865F4A84-7508-420C-BEBC-E4BD0324660E"
            },
            {
              "criteria": "cpe:2.3:a:hp:oneview:5.20.01:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A9FF0533-884C-45FB-9DBF-4F77C487347A"
            },
            {
              "criteria": "cpe:2.3:a:hp:synergy_composer:5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C1E24806-A07A-4853-B37E-368A4369C00E"
            },
            {
              "criteria": "cpe:2.3:a:hp:synergy_composer:5.00.01:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E5B6C01F-58F2-4AB7-87F1-4775772EC228"
            },
            {
              "criteria": "cpe:2.3:a:hp:synergy_composer:5.00.02:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C0D75A78-597D-4869-AF93-A7713EA3FC55"
            },
            {
              "criteria": "cpe:2.3:a:hp:synergy_composer:5.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "31B4B2A0-1049-4EA8-8201-CFDE0299CC46"
            },
            {
              "criteria": "cpe:2.3:a:hp:synergy_composer:5.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8F2F7A90-DBF6-494B-B5C7-A8FDCF963E0B"
            },
            {
              "criteria": "cpe:2.3:a:hp:synergy_composer:5.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "218EB5A1-5577-4779-88AC-48D11E202E6F"
            },
            {
              "criteria": "cpe:2.3:a:hp:synergy_composer:5.20.01:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2725D03B-CE0C-4257-9ADC-12A3B8132BC4"
            },
            {
              "criteria": "cpe:2.3:a:hp:synergy_composer_2:5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "86502D50-9271-4E97-AED8-B9F2D408A544"
            },
            {
              "criteria": "cpe:2.3:a:hp:synergy_composer_2:5.00.01:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "269EA18C-C73B-42A4-926D-41D8E891859A"
            },
            {
              "criteria": "cpe:2.3:a:hp:synergy_composer_2:5.00.02:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0D446953-7DE9-4B44-A3BD-E7F37A42203F"
            },
            {
              "criteria": "cpe:2.3:a:hp:synergy_composer_2:5.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2889CE0D-6C92-4D9D-82E4-5F787A81498F"
            },
            {
              "criteria": "cpe:2.3:a:hp:synergy_composer_2:5.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F8BDAE9F-F232-420E-8C9B-DF7749C2F80F"
            },
            {
              "criteria": "cpe:2.3:a:hp:synergy_composer_2:5.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E4407C0B-E515-4094-A014-60F933C6A95F"
            },
            {
              "criteria": "cpe:2.3:a:hp:synergy_composer_2:5.20.01:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3114FF14-591B-4B58-AC55-98E06E7BE813"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-alert@hpe.com"
}