PT-2002-1320 · Hewlett Packard · Hp Advancestack Hubs
Published
2002-05-29
·
Updated
2016-10-18
·
CVE-2002-0250
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
HP AdvanceStack hubs J3200A through J3210A with firmware version A.03.07 and earlier
Description
The web configuration utility in the affected HP AdvanceStack hubs allows unauthorized users to bypass authentication. This can be achieved by making a direct HTTP request to the "web access.html" file. As a result, an unauthorized user can change the switch's configuration and modify the administrator password.
Recommendations
For HP AdvanceStack hubs J3200A through J3210A with firmware version A.03.07 and earlier, consider restricting access to the web configuration utility until a patch is available. As a temporary workaround, avoid using the web access.html file for configuration changes.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hp Advancestack Hubs