CVE-2021-26587
Estado: ModificadaMedia (6.5)—
A potential DOM-based Cross Site Scripting security vulnerability has been identified in HPE StoreOnce. The vulnerability could be remotely exploited to cause an elevation of privilege leading to partial impact to confidentiality, availability, and integrity. HPE has made the following software update - HPE StoreOnce 4.3.0, to resolve the vulnerability in HPE StoreOnce.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.50%
- Percentil entre todas las CVEs puntuadas: 41
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (6)
CWE
- CWE-79
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-26587",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:S/C:P/I:P/A:P",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 6.8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 3.7,
"exploitabilityScore": 2.3
}
]
},
"affected": [
{
"source": "security-alert@hpe.com",
"affectedData": [
{
"vendor": "n/a",
"product": "HPE StoreOnce 3620; HPE StoreOnce 3640; HPE StoreOnce 5200; HPE StoreOnce 5250; HPE StoreOnce 5650; HPE StoreOnce VSA 4TB",
"versions": [
{
"status": "affected",
"version": "Firmware version: 4.2.3 and earlier"
},
{
"status": "affected",
"version": "FW version: 4.2.3 and earlier"
}
]
}
]
}
],
"published": "2021-09-27T15:15:07.513",
"references": [
{
"url": "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst04176en_us",
"tags": [
"Vendor Advisory"
],
"source": "security-alert@hpe.com"
},
{
"url": "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst04176en_us",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A potential DOM-based Cross Site Scripting security vulnerability has been identified in HPE StoreOnce. The vulnerability could be remotely exploited to cause an elevation of privilege leading to partial impact to confidentiality, availability, and integrity. HPE has made the following software update - HPE StoreOnce 4.3.0, to resolve the vulnerability in HPE StoreOnce."
},
{
"lang": "es",
"value": "Se ha identificado una posible vulnerabilidad de seguridad de tipo Cross Site Scripting basada en DOM en HPE StoreOnce. La vulnerabilidad podría ser explotada remotamente para causar una elevación de privilegios que conlleva a un impacto parcial en la confidencialidad, la disponibilidad y la integridad. HPE ha realizado la siguiente actualización de software - HPE StoreOnce versión 4.3.0, para resolver la vulnerabilidad en HPE StoreOnce"
}
],
"lastModified": "2026-06-17T03:43:31.540",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:hpe:storeonce_5200_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "53AB0828-FF53-4733-BE40-5EF0EBCE5D90",
"versionEndIncluding": "4.2.3"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:hpe:storeonce_5200:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "279A8D38-05FA-452D-AAC4-BA58FD5DD04C"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:hpe:storeonce_5650_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "429ED84E-7274-4FFC-A57A-C8CAA91FB5D9",
"versionEndIncluding": "4.2.3"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:hpe:storeonce_5650:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1EDCC6E4-0E66-4263-A610-D17ACC072A1F"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:hpe:storeonce_5250_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "53741142-DFCA-42DB-A666-6784FB659DBA",
"versionEndIncluding": "4.2.3"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:hpe:storeonce_5250:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "398942BB-98D1-4CBD-9A65-A05F979806EF"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:hpe:storeonce_3640_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AEAA609A-AD41-4097-8112-990AEB5B5565",
"versionEndIncluding": "4.2.3"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:hpe:storeonce_3640:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "963FF36A-EB2F-4828-BCAC-9E22F8F4F838"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:hpe:storeonce_3620_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B1F673C7-3DA8-4F12-ACAE-2CDB09086B60",
"versionEndIncluding": "4.2.3"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:hpe:storeonce_3620:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "80CE5CAD-48C5-4FAE-B3DD-DF96BFB516B4"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:hpe:storeonce_vsa_4tb_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B6B31C2D-8038-414D-88A0-95965AF6D90A",
"versionEndIncluding": "4.2.3"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:hpe:storeonce_vsa_4tb:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "0F7C0CF6-31B7-4D24-93D7-3E4EEB5281A9"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "security-alert@hpe.com"
}