Executive Summary

Summary
Title HP Virtual Connect Enterprise Manager (VCEM) for Windows, Remote Arbitrary File Download
Informations
Name HPSBMA02593 SSRT100237 First vendor Publication 2010-10-21
Vendor HP Last vendor Modification 2010-10-21
Severity (Vendor) N/A Revision 1

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:P/I:N/A:N)
Cvss Base Score 5 Attack Range Network
Cvss Impact Score 2.9 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

A potential security vulnerability has been identified in HP Virtual Connect Enterprise Manager (VCEM) for Windows. The vulnerability could be exploited remotely to download arbitrary files.

Original Source

Url : http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02550412

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 2

Open Source Vulnerability Database (OSVDB)

Id Description
68825 HP Virtual Connect Enterprise Manager Unspecified Arbitrary File Access

HP Virtual Connect Enterprise Manager contains an unspecified flaw that may allow a remote attacker to access arbitrary files. No further details have been provided.

Nessus® Vulnerability Scanner

Date Description
2010-11-11 Name : The remote host contains a web application that is affected by an authenticat...
File : hp_sim_plugins_authentication_bypass.nasl - Type : ACT_ATTACK