Improper Authentication in HPE products - CVE-2022-28620
Published: June 23, 2022 / Updated: June 23, 2022
Vulnerability identifier: #VU64617
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-28620
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to improper authentication. A remote unauthenticated attacker can bypass authentication and gain unauthorized access to the system.
Affected software
Cray Legacy Shasta System Solutions
Slingshot
Cray EX Supercomputer
Slingshot
Cray EX Supercomputer
How to mitigate CVE-2022-28620
Install updates from vendor's website.
Cray Legacy Shasta System Solutions - addressed in versions 1.4.27, 1.5.33, 1.6.27
Cray EX Supercomputer - addressed in versions 1.4.27, 1.5.33, 1.6.27
Slingshot - update to 1.7.2
Cray EX Supercomputer - addressed in versions 1.4.27, 1.5.33, 1.6.27
Slingshot - update to 1.7.2