CVE-2019-11996: HPE Nimbleos

Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.

Potential security vulnerabilities have been identified with HPE Nimble Storage systems in multi array group configurations. The vulnerabilities could be exploited by an attacker to gain elevated privileges on the array. The following NimbleOS versions, and all subsequent releases, contain a software fix for this vulnerability: 3.9.2.0, 4.5.5.0, 5.0.8.0 and 5.1.3.0.

Affected products

  • HPE Nimbleos: from 3.1.0.0, up to and including 3.9.1.0; from 4.1.0.0, up to and including 4.5.4.0; from 5.0.1.0, up to and including 5.0.7.0; from 5.1.0.0, up to and including 5.1.2.0

Published 2019-11-07. Last modified 2026-06-17.