{"api_version":"1","generated_at":"2026-07-23T07:28:07+00:00","cve":"CVE-2016-8529","urls":{"html":"https://cve.report/CVE-2016-8529","api":"https://cve.report/api/cve/CVE-2016-8529.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-8529","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-8529"},"summary":{"title":"CVE-2016-8529","description":"A Remote Arbitrary Command Execution vulnerability in HPE StoreVirtual 4000 Storage and StoreVirtual VSA Software running LeftHand OS version v12.5 and earlier was found. The problem was resolved in LeftHand OS v12.6 or any subsequent version.","state":"PUBLIC","assigner":"security-alert@hpe.com","published_at":"2018-02-15 22:29:00","updated_at":"2018-03-12 18:47:00"},"problem_types":["CWE-284"],"metrics":[],"references":[{"url":"https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-c05382958","name":"https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-c05382958","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Document Display | HPE Support Center","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/95970","name":"95970","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Multiple HP Products CVE-2016-8529 Unspecified Remote Code Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securitytracker.com/id/1037762","name":"1037762","refsource":"SECTRACK","tags":["Third Party Advisory","VDB Entry"],"title":"HPE StoreVirtual Storage Unspecified Flaw Lets Remote Authenticated Users Execute Arbitrary Commands on the Target System - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-8529","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-8529","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"8529","vulnerable":"1","versionEndIncluding":"12.5","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"hp","cpe5":"lefthand","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security-alert@hpe.com","DATE_PUBLIC":"2017-01-31T00:00:00","ID":"CVE-2016-8529","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"StoreVirtual 4000 Storage and StoreVirtual VSA Software running LeftHand OS","version":{"version_data":[{"version_value":"LeftHand OS v12.5 and earlier"}]}}]},"vendor_name":"Hewlett Packard Enterprise"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A Remote Arbitrary Command Execution vulnerability in HPE StoreVirtual 4000 Storage and StoreVirtual VSA Software running LeftHand OS version v12.5 and earlier was found. The problem was resolved in LeftHand OS v12.6 or any subsequent version."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Remote Arbitrary Command Execution"}]}]},"references":{"reference_data":[{"name":"1037762","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1037762"},{"name":"https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-c05382958","refsource":"CONFIRM","url":"https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-c05382958"},{"name":"95970","refsource":"BID","url":"http://www.securityfocus.com/bid/95970"}]}},"nvd":{"publishedDate":"2018-02-15 22:29:00","lastModifiedDate":"2018-03-12 18:47:00","problem_types":["CWE-284"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"HIGH","baseScore":7.6,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":4.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:A/AC:L/Au:N/C:P/I:P/A:C","accessVector":"ADJACENT_NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"COMPLETE","baseScore":7.3},"severity":"HIGH","exploitabilityScore":6.5,"impactScore":8.5,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:hp:lefthand:*:*:*:*:*:*:*:*","versionEndIncluding":"12.5","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"8529","Ordinal":"95183","Title":"CVE-2016-8529","CVE":"CVE-2016-8529","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"8529","Ordinal":"1","NoteData":"A Remote Arbitrary Command Execution vulnerability in HPE StoreVirtual 4000 Storage and StoreVirtual VSA Software running LeftHand OS version v12.5 and earlier was found. The problem was resolved in LeftHand OS v12.6 or any subsequent version.","Type":"Description","Title":null},{"CveYear":"2016","CveId":"8529","Ordinal":"2","NoteData":"2018-02-15","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"8529","Ordinal":"3","NoteData":"2018-02-16","Type":"Other","Title":"Modified"}]}}}