CVE-2019-12002: HPE Msa 1040 Firmware

Critical severity, CVSS 9.8. EPSS: 2.2% chance of exploitation in the next 30 days.

A remote session reuse vulnerability leading to access restriction bypass was discovered in HPE MSA 2040 SAN Storage; HPE MSA 1040 SAN Storage; HPE MSA 1050 SAN Storage; HPE MSA 2042 SAN Storage; HPE MSA 2050 SAN Storage; HPE MSA 2052 SAN Storage version(s): GL225P001 and earlier; GL225P001 and earlier; VE270R001-01 and earlier; GL225P001 and earlier; VL270R001-01 and earlier; VL270R001-01 and earlier.

Affected products

  • HPE Msa 1040 Firmware: up to and including gl225p001
  • HPE Msa 1050 Firmware: up to and including ve270r001-01
  • HPE Msa 2040 Firmware: up to and including gl225p001
  • HPE Msa 2042 Firmware: up to and including gl225p001
  • HPE Msa 2050 Firmware: up to and including vl270r001-01
  • HPE Msa 2052 Firmware: up to and including vl270r001-01

Published 2020-04-17. Last modified 2026-06-17.