A potential security vulnerability has been identified in HPE StoreOnce Software. The SSH server supports weak key exchange algorithms which could lead to remote unauthorized access. HPE has made the following software update to resolve the vulnerability in HPE StoreOnce Software 4.3.2.
References
Link | Resource |
---|---|
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst04311en_us | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
07 Jul 2022, 18:29
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-327 | |
CPE | cpe:2.3:h:hpe:storeonce_3640:-:*:*:*:*:*:*:* cpe:2.3:o:hpe:storeonce_3640_firmware:*:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : 5.0
v3 : 7.5 |
References | (MISC) https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst04311en_us - Vendor Advisory |
27 Jun 2022, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-06-27 19:15
Updated : 2024-02-04 22:29
NVD link : CVE-2022-28622
Mitre link : CVE-2022-28622
CVE.ORG link : CVE-2022-28622
JSON object : View
Products Affected
hpe
- storeonce_3640
- storeonce_3640_firmware
CWE
CWE-327
Use of a Broken or Risky Cryptographic Algorithm