CVE-2022-37940 MEDIUM

CVE-2022-37940

Vendor Hewlett Packard Enterprise (Hpe)
Product HPE FlexFabric 5700 Switch Series
Published March 15, 2023
Last update February 27, 2025

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

What the vulnerability does

01Description

Potential security vulnerabilities have been identified in the HPE FlexFabric 5700 Switch Series. These vulnerabilities could be remotely exploited to allow host header injection and URL redirection. HPE has made the following software to resolve the vulnerability in HPE FlexFabric 5700 Switch Series version R2432P61 or later.

Key dates

02Disclosure timeline

March 15, 2023 CVE published
February 27, 2025 Record updated