PT-2012-5359 · Hewlett Packard · Hp San/Iq

Nicolas Gregoire

·

Publicado

2012-08-20

·

Atualizado

2012-08-21

·

CVE-2012-4362

CVSS v2.0

4.0

Média

VetorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions HP SAN/iQ versions prior to 9.5
Description The issue concerns a hardcoded password in hydra.exe for the global$agent account. This hardcoded password is L0CAlu53R, allowing remote attackers to gain access to a management service. The attack vector involves sending a login request to TCP port 13838.
Recommendations For HP SAN/iQ versions prior to 9.5, change the hardcoded password L0CAlu53R for the global$agent account to prevent unauthorized access. As a temporary workaround, consider restricting access to TCP port 13838 until the issue is resolved.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-4362

Produtos afetados

Hp San/Iq