#VU117396 Command Injection in HPE products - CVE-2022-28618
Published: October 20, 2025
Vulnerability identifier: #VU117396
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2022-28618
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
Nimble Storage Hybrid Flash Arrays
Nimble Storage All Flash Arrays
Nimble Storage Secondary Flash Arrays
Nimble Storage Hybrid Flash Arrays
Nimble Storage All Flash Arrays
Nimble Storage Secondary Flash Arrays
Software vendor:
HPE
HPE
Description
The vulnerability allows a remote privileged user to execute arbitrary commands on the system.
The vulnerability exists due to insufficient input validation. A remote privileged user can pass specially crafted data to the application and execute arbitrary commands.
Remediation
Install updates from vendor's website.