CVE-2013-2352

LeftHand OS (aka SAN iQ) 10.5 and earlier on HP StoreVirtual Storage devices does not provide a mechanism for disabling the HP Support challenge-response root-login feature, which makes it easier for remote attackers to obtain administrative access by leveraging knowledge of an unused one-time password.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:hp:san\/iq:*:*:*:*:*:*:*:*
cpe:2.3:a:hp:san\/iq:8.0:*:*:*:*:*:*:*
cpe:2.3:a:hp:san\/iq:8.1:*:*:*:*:*:*:*
cpe:2.3:a:hp:san\/iq:8.5:*:*:*:*:*:*:*
cpe:2.3:a:hp:san\/iq:9.0:*:*:*:*:*:*:*
cpe:2.3:a:hp:san\/iq:9.5:*:*:*:*:*:*:*
cpe:2.3:a:hp:san\/iq:10.0:*:*:*:*:*:*:*
OR cpe:2.3:h:dell:poweredge_2950:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:dl320s:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:lefthand_nsm2060:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:lefthand_nsm2060_g2:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:lefthand_nsm2120_g2:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:lefthand_vsa:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:p4000_vsa:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:p4300:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:p4300_g2:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:p4500:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:p4500_g2:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:p4900_g2:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:storevirtual_4130:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:storevirtual_4330:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:storevirtual_4530:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:storevirtual_4630:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:storevirtual_4730:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:storevirtual_vsa:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:x3650:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2013-07-10 22:55

Updated : 2023-12-10 11:16


NVD link : CVE-2013-2352

Mitre link : CVE-2013-2352

CVE.ORG link : CVE-2013-2352


JSON object : View

Products Affected

hp

  • p4300
  • storevirtual_4530
  • p4500
  • lefthand_vsa
  • lefthand_nsm2060_g2
  • storevirtual_4330
  • storevirtual_4630
  • san\/iq
  • p4300_g2
  • p4900_g2
  • storevirtual_4730
  • dl320s
  • storevirtual_4130
  • lefthand_nsm2060
  • lefthand_nsm2120_g2
  • storevirtual_vsa
  • p4000_vsa
  • p4500_g2

dell

  • poweredge_2950

ibm

  • x3650
CWE
CWE-255

Credentials Management Errors