LeftHand OS (aka SAN iQ) 10.5 and earlier on HP StoreVirtual Storage devices does not provide a mechanism for disabling the HP Support challenge-response root-login feature, which makes it easier for remote attackers to obtain administrative access by leveraging knowledge of an unused one-time password.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Dell
Subscribe
|
Poweredge 2950
Subscribe
|
|
Hp
Subscribe
|
Dl320s
Subscribe
Lefthand Nsm2060
Subscribe
Lefthand Nsm2060 G2
Subscribe
Lefthand Nsm2120 G2
Subscribe
Lefthand Vsa
Subscribe
P4000 Vsa
Subscribe
P4300
Subscribe
P4300 G2
Subscribe
P4500
Subscribe
P4500 G2
Subscribe
P4900 G2
Subscribe
San\/iq
Subscribe
Storevirtual 4130
Subscribe
Storevirtual 4330
Subscribe
Storevirtual 4530
Subscribe
Storevirtual 4630
Subscribe
Storevirtual 4730
Subscribe
Storevirtual Vsa
Subscribe
|
|
Ibm
Subscribe
|
X3650
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2013-2298 | LeftHand OS (aka SAN iQ) 10.5 and earlier on HP StoreVirtual Storage devices does not provide a mechanism for disabling the HP Support challenge-response root-login feature, which makes it easier for remote attackers to obtain administrative access by leveraging knowledge of an unused one-time password. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: hp
Published:
Updated: 2024-09-16T16:37:31.666Z
Reserved: 2013-03-04T00:00:00Z
Link: CVE-2013-2352
No data.
Status : Deferred
Published: 2013-07-10T22:55:00.953
Modified: 2025-04-11T00:51:21.963
Link: CVE-2013-2352
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD