Executive Summary

Summary
Title HP LeftHand Virtual SAN Appliance hydra, Remote Execution of Arbitrary Code
Informations
Name HPSBST02846 SSRT100798 First vendor Publication 2013-02-05
Vendor HP Last vendor Modification 2013-06-28
Severity (Vendor) N/A Revision N/A

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C)
Cvss Base Score 10 Attack Range Network
Cvss Impact Score 10 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Potential security vulnerabilities have been identified with HP LeftHand Virtual SAN Appliance hydra. The vulnerabilities could be remotely exploited resulting in execution of arbitrary code.

Original Source

Url : http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03661318

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 1
Application 1
Application 4

SAINT Exploits

Description Link
HP LeftHand Virtual SAN Appliance Hydra Service Login Buffer Overflow More info here
HP LeftHand Virtual SAN Appliance hydra Ping Hostname Overflow More info here

Snort® IPS/IDS

Date Description
2014-03-06 HP LeftHand Virtual SAN hydra information disclosure attempt
RuleID : 29517 - Revision : 3 - Type : SERVER-OTHER
2014-03-06 HP LeftHand Virtual SAN hydra information disclosure attempt
RuleID : 29516 - Revision : 4 - Type : SERVER-OTHER
2014-01-10 HP LeftHand Virtual SAN hydra login request buffer overflow attempt
RuleID : 27646 - Revision : 6 - Type : SERVER-OTHER
2014-01-10 HP LeftHand Virtual SAN hydra snmp request buffer overflow attempt
RuleID : 26336 - Revision : 6 - Type : SERVER-OTHER
2014-01-10 HP LeftHand Virtual SAN hydra diag request buffer overflow attempt
RuleID : 26334 - Revision : 6 - Type : SERVER-OTHER
2014-01-10 HP LeftHand Virtual SAN hydra diag request buffer overflow attempt
RuleID : 26333 - Revision : 6 - Type : SERVER-OTHER
2014-01-10 HP LeftHand Virtual SAN hydra ping request buffer overflow attempt
RuleID : 26103 - Revision : 9 - Type : SERVER-OTHER

Nessus® Vulnerability Scanner

Date Description
2013-02-14 Name : A management service on the remote host has multiple remote code execution vu...
File : hp_vsa_10_0.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
1
2
3
Date Informations
2013-07-03 13:29:48
  • Multiple Updates
2013-07-02 05:18:14
  • Multiple Updates
2013-02-06 21:22:18
  • Multiple Updates
2013-02-05 21:19:31
  • First insertion