CVE-2022-37939
low-risk
Published 2023-03-10
A potential security vulnerability has been identified in HPE Superdome Flex and Superdome Flex 280 servers. The vulnerability could be locally exploited to allow disclosure of information. HPE has made the following software to resolve the vulnerability in HPE Superdome Flex Servers v3.65.8 and Superdome Flex 280 Servers v1.45.8.
Do I need to act?
-
0.11% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
2
CVSS 2.3/10
Low
LOCAL
/ LOW complexity
Affected Products (2)
Superdome Flex 280 Server Firmware
Superdome Flex Server Firmware
Affected Vendors
References (2)
17
/ 100
low-risk
Severity
10/34 · Low
Exploitability
0/34 · Minimal
Exposure
7/34 · Low