Description
LeftHand OS (aka SAN iQ) 10.5 and earlier on HP StoreVirtual Storage devices does not provide a mechanism for disabling the HP Support challenge-response root-login feature, which makes it easier for remote attackers to obtain administrative access by leveraging knowledge of an unused one-time password.
Published: 2013-07-10
Score: 9.4 Critical
EPSS: 2.3% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2013-2298 LeftHand OS (aka SAN iQ) 10.5 and earlier on HP StoreVirtual Storage devices does not provide a mechanism for disabling the HP Support challenge-response root-login feature, which makes it easier for remote attackers to obtain administrative access by leveraging knowledge of an unused one-time password.
History

No history.

Subscriptions

Dell Poweredge 2950
Hp Dl320s Lefthand Nsm2060 Lefthand Nsm2060 G2 Lefthand Nsm2120 G2 Lefthand Vsa P4000 Vsa P4300 P4300 G2 P4500 P4500 G2 P4900 G2 San\/iq Storevirtual 4130 Storevirtual 4330 Storevirtual 4530 Storevirtual 4630 Storevirtual 4730 Storevirtual Vsa
Ibm X3650
cve-icon MITRE

Status: PUBLISHED

Assigner: hp

Published:

Updated: 2024-09-16T16:37:31.666Z

Reserved: 2013-03-04T00:00:00.000Z

Link: CVE-2013-2352

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2013-07-10T22:55:00.953

Modified: 2025-04-11T00:51:21.963

Link: CVE-2013-2352

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses