Command Injection in HPE products - CVE-2022-28618

 

Command Injection in HPE products - CVE-2022-28618

Published: October 20, 2025


Vulnerability identifier: #VU117396
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-28618
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote privileged user to execute arbitrary commands on the system.

The vulnerability exists due to insufficient input validation. A remote privileged user can pass specially crafted data to the application and execute arbitrary commands.


Affected software

Nimble Storage Hybrid Flash Arrays
Nimble Storage All Flash Arrays
Nimble Storage Secondary Flash Arrays

How to mitigate CVE-2022-28618

Install updates from vendor's website.

Nimble Storage Hybrid Flash Arrays - addressed in versions 5.0.10.100, 5.2.1.500, 6.0.0.100
Nimble Storage All Flash Arrays - addressed in versions 5.0.10.100, 5.2.1.500, 6.0.0.100
Nimble Storage Secondary Flash Arrays - addressed in versions 5.0.10.100, 5.2.1.500, 6.0.0.100

External References

Related Security Bulletins