CVE-2020-7198

There is a remote escalation of privilege possible for a malicious user that has a OneView account in OneView and Synergy Composer. HPE has provided updates to Oneview and Synergy Composer: Update to version 5.5 of OneView, Composer, or Composer2.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
hpeCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 52%
VendorProductVersion
hponeview
5.0
hponeview
5.00.01
hponeview
5.00.02
hponeview
5.2
hponeview
5.3
hponeview
5.4
hponeview
5.20.01
hpsynergy_composer
5.0
hpsynergy_composer
5.00.01
hpsynergy_composer
5.00.02
hpsynergy_composer
5.2
hpsynergy_composer
5.3
hpsynergy_composer
5.4
hpsynergy_composer
5.20.01
hpsynergy_composer_2
5.0
hpsynergy_composer_2
5.00.01
hpsynergy_composer_2
5.00.02
hpsynergy_composer_2
5.2
hpsynergy_composer_2
5.3
hpsynergy_composer_2
5.4
hpsynergy_composer_2
5.20.01
𝑥
= Vulnerable software versions