mirror of
https://github.com/0xMarcio/cve.git
synced 2026-06-01 23:31:36 +02:00
882 B
882 B
CVE-2013-2352
Description
LeftHand OS (aka SAN iQ) 10.5 and earlier on HP StoreVirtual Storage devices does not provide a mechanism for disabling the HP Support challenge-response root-login feature, which makes it easier for remote attackers to obtain administrative access by leveraging knowledge of an unused one-time password.
POC
Reference
- http://www.theregister.co.uk/2013/07/09/hp_storage_more_possible_backdoors/
- http://www.theregister.co.uk/2013/07/09/hp_storage_more_possible_backdoors/