CVE-2019-11994 is a critical directory traversal vulnerability affecting multiple HPE SimpliVity products running OmniStack version 3.7.9 and earlier. An unauthenticated attacker can exploit an API accessible over the management network to execute arbitrary command manifest files on affected nodes. This allows for unauthenticated remote code execution, leading to complete compromise of confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code, the vulnerability has a high CVSS score of 9.8 and significant community discussion, indicating potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.6.2, <= 3.7.9CPE matchmatch criteria | cpe:2.3:o:hp:simplivity_380_gen9_firmware:*:*:*:*:*:*:*:* | ||
>= 3.7.8, <= 3.7.9CPE matchmatch criteria | cpe:2.3:o:hp:simplivity_380_gen10_g_firmware:*:*:*:*:*:*:*:* | ||
>= 3.7.1, <= 3.7.9CPE matchmatch criteria | cpe:2.3:o:hp:simplivity_380_gen10_firmware:*:*:*:*:*:*:*:* | ||
>= 3.7.5, <= 3.7.9CPE matchmatch criteria | cpe:2.3:o:hp:simplivity_2600_gen10_firmware:*:*:*:*:*:*:*:* | ||
>= 3.5.2, <= 3.7.9CPE matchmatch criteria | cpe:2.3:o:hp:simplivity_omnicube_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.