CVE-2022-37940 describes potential security vulnerabilities in the HPE FlexFabric 5700 Switch Series, specifically affecting various models like the 40XG and 48G switches and their firmware. This medium-severity vulnerability (CVSS 6.1) allows for remote host header injection and URL redirection, requiring user interaction but with low attack complexity and potential for partial confidentiality and integrity impact. While HPE has released software version R2432P61 or later to resolve the issue, there is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< r2432p61CPE matchmatch criteria | cpe:2.3:o:hpe:flexfabric_5700_40xg_2qsfp\+_firmware:*:*:*:*:*:*:*:* | ||
< r2432p61CPE matchmatch criteria | cpe:2.3:o:hpe:flexfabric_5700_48g_4xg_2qsfp\+_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.