PT-2007-6114 · Hewlett Packard · Hp-Ux
Published
2007-09-18
·
Updated
2017-09-29
·
CVE-2007-5008
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
HP-UX versions B.11.11, B.11.23, B.11.31
Description
The issue concerns the logins command, which fails to correctly report password status. This allows remote attackers to gain privileges under certain conditions when password issues are not properly detected.
Recommendations
For HP-UX version B.11.11, update to a version that correctly reports password status.
For HP-UX version B.11.23, update to a version that correctly reports password status.
For HP-UX version B.11.31, update to a version that correctly reports password status.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hp-Ux