CVE-2019-11991: HP 3par Service Processor Firmware

Critical severity, CVSS 9.8. EPSS: 4.7% chance of exploitation in the next 30 days.

HPE has identified a vulnerability in HPE 3PAR Service Processor (SP) version 4.1 through 4.4. HPE 3PAR Service Processor (SP) version 4.1 through 4.4 has a remote information disclosure vulnerability which can allow for the disruption of the confidentiality, integrity and availability of the Service Processor and any managed 3PAR arrays.

Affected products

  • HP 3par Service Processor Firmware: from 4.1, up to and including 4.4

Published 2019-07-09. Last modified 2026-06-17.