PT-2002-1320 · Hewlett Packard · Hp Advancestack Hubs

Publicado

2002-05-29

·

Atualizado

2016-10-18

·

CVE-2002-0250

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions HP AdvanceStack hubs J3200A through J3210A with firmware version A.03.07 and earlier
Description The web configuration utility in the affected HP AdvanceStack hubs allows unauthorized users to bypass authentication. This can be achieved by making a direct HTTP request to the "web access.html" file. As a result, an unauthorized user can change the switch's configuration and modify the administrator password.
Recommendations For HP AdvanceStack hubs J3200A through J3210A with firmware version A.03.07 and earlier, consider restricting access to the web configuration utility until a patch is available. As a temporary workaround, avoid using the web access.html file for configuration changes.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-0250

Produtos afetados

Hp Advancestack Hubs