CVE-2020-8583

4 documents4 sources
Severity
7.5HIGH
EPSS
0.3%
top 44.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 13
Latest updateMay 24

Description

Element Software versions prior to 12.2 and HCI versions prior to 1.8P1 are susceptible to a vulnerability which could allow an attacker to discover sensitive information by intercepting its transmission within an https session.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

CVEListV5netapp_solidfire_&_hci_storage_node_(element_software)_)Element Software versions prior to 12.2 and HCI versions prior to 1.8P1
NVDnetapp/element_os10.012.2
NVDnetapp/hci1.8

🔴Vulnerability Details

2
GHSA
GHSA-q4v7-mpx5-4v38: Element Software versions prior to 122022-05-24
CVEList
CVE-2020-8583: Element Software versions prior to 122020-11-13

💬Community

1
Bugzilla
CVE-2019-8583 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution2020-09-08
CVE-2020-8583 (HIGH CVSS 7.5) | Element Software versions prior to | cvebase.io