AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-28620

CRITICAL · CVSS 9.8 EPSS 1.47%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-06-24 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.8. It may be remotely exploitable.

CVE
CVE-2022-28620
Severity
CRITICAL
CVSS
9.8
EPSS
1.47%

Original NVD Description

A remote authentication bypass vulnerability was discovered in HPE Cray Legacy Shasta System Solutions; HPE Slingshot; and HPE Cray EX supercomputers versions: Prior to node controller firmware associated with HPE Cray EX liquid cooled blades, and all versions of chassis controller firmware associated with HPE Cray EX liquid cooled cabinets prior to 1.6.27/1.5.33/1.4.27; All Slingshot versions prior to 1.7.2; All versions of node controller firmware associated with HPE Cray EX liquid cooled blades, and all versions of chassis controller firmware associated with HPE Cray EX liquid cooled cabinets prior to 1.6.27/1.5.33/1.4.27. HPE has provided a software update to resolve this vulnerability in HPE Cray Legacy Shasta System Solutions, HPE Slingshot, and HPE Cray EX Supercomputers.

Related CVEs

Other vulnerabilities affecting the same vendor(s)