PT-2002-1320 · Hewlett Packard · Hp Advancestack Hubs
Publicado
2002-05-29
·
Atualizado
2016-10-18
·
CVE-2002-0250
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
HP AdvanceStack hubs J3200A through J3210A with firmware version A.03.07 and earlier
Description
The web configuration utility in the affected HP AdvanceStack hubs allows unauthorized users to bypass authentication. This can be achieved by making a direct HTTP request to the "web access.html" file. As a result, an unauthorized user can change the switch's configuration and modify the administrator password.
Recommendations
For HP AdvanceStack hubs J3200A through J3210A with firmware version A.03.07 and earlier, consider restricting access to the web configuration utility until a patch is available. As a temporary workaround, avoid using the web access.html file for configuration changes.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Hp Advancestack Hubs