Known vulnerabilities in HPE SANnav Management Software

Vendor: HPE
Software CPE: cpe:2.3:a:hpe:hpe_sannav_management_software:*:*:*:*:*:*:*:*
Total vulnerabilities: 17
Public exploits: 4
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting HPE SANnav Management Software HPE SANnav Management Software is affected by 17 known vulnerabilities: 1 critical, 2 high, 6 medium, 8 low Critical High Medium Low

Vulnerabilities (17)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU86768 - Improper Authentication
CVE-2023-52160
CWE-287 Medium
Available
No
2.3.0a 23.02.2024 SB2024022343
SB2024022345
SB2024022346
and 11 more
#VU69278 - Exposure of sensitive information to an unauthorized actor
CVE-2022-43936
CWE-200 Low
No
No
2.2.2 14.11.2022 SB2022111417
#VU69277 - Exposure of sensitive information to an unauthorized actor
CVE-2022-43935
CWE-200 Low
No
No
2.2.2 14.11.2022 SB2022111417
#VU69276 - Exposure of sensitive information to an unauthorized actor
CVE-2022-43934
CWE-200 Medium
No
No
2.2.2 14.11.2022 SB2022111417
#VU69275 - Exposure of sensitive information to an unauthorized actor
CVE-2022-43933
CWE-200 Low
No
No
2.2.2 14.11.2022 SB2022111417
#VU69274 - Exposure of sensitive information to an unauthorized actor
CVE-2022-33187
CWE-200 Low
No
No
2.2.1, 2.2.2 14.11.2022 SB2022111415
#VU64656 - Use of Hard-coded Cryptographic Key
CVE-2022-28166
CWE-321 Medium
No
No
2.1.1.8, 2.2.0.2 24.06.2022 SB2022062423
SB2022062820
SB2022092608
#VU64655 - Missing Encryption of Sensitive Data
CVE-2022-28167
CWE-311 Low
No
No
2.1.1.8, 2.2.0.2 24.06.2022 SB2022062423
SB2022062820
SB2022092608
#VU64653 - Missing Encryption of Sensitive Data
CVE-2022-28168
CWE-311 Low
No
No
2.1.1.8, 2.2.0.2 24.06.2022 SB2022062423
SB2022062820
SB2022092608
#VU59719 - Improper input validation
CVE-2022-21291
CWE-20 Medium
No
No
2.1.1.8, 2.2.0.2 18.01.2022 SB2022011840
SB2022011841
SB2022011931
and 67 more
#VU59720 - Improper input validation
CVE-2022-21305
CWE-20 Medium
No
No
2.1.1.8, 2.2.0.2 18.01.2022 SB2022011840
SB2022011841
SB2022011931
and 85 more
#VU58976 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-45046
CWE-94 High
Available
Exploited
2.1.1.7, 2.2.0.1 15.12.2021 SB2021121504
SB2021121511
SB2021121512
and 178 more
#VU58816 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-44228
CWE-94 Critical
Available
Exploited
2.1.1.7, 2.2.0.1 10.12.2021 SB2021121003
SB2021121101
SB2021121201
and 338 more
#VU55059 - Improper input validation
CVE-2021-2432
CWE-20 Low
No
No
2.1.1.8, 2.2.0.2 20.07.2021 SB2021072054
SB2021083016
SB2021091525
and 31 more
#VU55057 - Improper input validation
CVE-2021-2388
CWE-20 Medium
No
No
2.1.1.8, 2.2.0.2 20.07.2021 SB2021072054
SB2021072055
SB2021072201
and 62 more
#VU53543 - Off-by-one Error
CVE-2021-23017
CWE-193 High
Available
No
2.1.1.8, 2.2.0.2 25.05.2021 SB2021052543
SB2021052713
SB2021052901
and 48 more
#VU17860 - Use of a Broken or Risky Cryptographic Algorithm
CVE-2019-1559
CWE-327 Low
No
No
2.1.1.8, 2.2.0.2 26.02.2019 SB2019022607
SB2019022802
SB2019022809
and 50 more