Vulnerabilities > CVE-2001-0374 - Security Bypass vulnerability in Web-Enabled Management

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
compaq
nessus

Summary

The HTTP server in Compaq web-enabled management software for (1) Foundation Agents, (2) Survey, (3) Power Manager, (4) Availability Agents, (5) Intelligent Cluster Administrator, and (6) Insight Manager can be used as a generic proxy server, which allows remote attackers to bypass access restrictions via the management port, 2301.

Vulnerable Configurations

Part Description Count
Application
Compaq
1

Nessus

NASL familyWeb Servers
NASL idDDI_COMPAQ_MGMT_PROXY.NASL
descriptionThe remote Compaq Web Management Agent install can be used as an HTTP proxy. An attacker can use this to bypass firewall rules or hide the source of web-based attacks.
last seen2020-06-01
modified2020-06-02
plugin id10963
published2002-05-22
reporterThis script is Copyright (C) 2002-2018 Digital Defense Inc.
sourcehttps://www.tenable.com/plugins/nessus/10963
titleCompaq Web-enabled Management Software HTTP Server Arbitrary Traffic Proxy