« Volver al listado

CVE-2020-8583

Estado: ModificadaAlta (7.5)—

Element Software versions prior to 12.2 and HCI versions prior to 1.8P1 are susceptible to a vulnerability which could allow an attacker to discover sensitive information by intercepting its transmission within an https session.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-8583",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security-alert@netapp.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "NetApp SolidFire & HCI Storage Node (Element Software) )",
          "versions": [
            {
              "status": "affected",
              "version": "Element Software versions prior to 12.2 and HCI versions prior to 1.8P1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-11-13T16:15:18.683",
  "references": [
    {
      "url": "https://security.netapp.com/advisory/NTAP-20201113-0008/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security-alert@netapp.com"
    },
    {
      "url": "https://security.netapp.com/advisory/NTAP-20201113-0008/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Element Software versions prior to 12.2 and HCI versions prior to 1.8P1 are susceptible to a vulnerability which could allow an attacker to discover sensitive information by intercepting its transmission within an https session."
    },
    {
      "lang": "es",
      "value": "Element Software versiones anteriores a 12.2 y HCI versiones anteriores a 1.8P1, son susceptibles a una vulnerabilidad que podría permitir a un atacante detectar información confidencial interceptando su transmisión dentro de una sesión https"
    }
  ],
  "lastModified": "2026-06-17T03:26:35.690",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:netapp:hci:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F48E1AF6-49BD-4EDE-BB8F-AF0B221C0ED9",
              "versionEndIncluding": "1.8"
            },
            {
              "criteria": "cpe:2.3:o:netapp:element_os:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8311FC1D-5FCC-4031-B4CF-931CDC91C956",
              "versionEndExcluding": "12.2",
              "versionStartIncluding": "10.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-alert@netapp.com"
}