PT-2021-17055 · Hewlett Packard · Hpe Network Orchestrator

Published

2021-03-18

·

Updated

2021-03-25

·

CVE-2021-26578

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions HPE Network Orchestrator (NetO) versions prior to 2.5
Description A potential security issue has been identified in HPE Network Orchestrator, which could be remotely exploited using SQL injection. This allows for information disclosure.
Recommendations For versions prior to 2.5, update to version 2.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the SQL database to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-26578
ZDI-21-337

Affected Products

Hpe Network Orchestrator