Vulnerabilities > CVE-2002-0250 - Authentication Bypass vulnerability in HP AdvanceStack Switch

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
hp
exploit available

Summary

Web configuration utility in HP AdvanceStack hubs J3200A through J3210A with firmware version A.03.07 and earlier, allows unauthorized users to bypass authentication via a direct HTTP request to the web_access.html file, which allows the user to change the switch's configuration and modify the administrator password.

Exploit-Db

descriptionHP AdvanceStack Switch Authentication Bypass Vulnerability. CVE-2002-0250 . Remote exploit for hardware platform
idEDB-ID:21285
last seen2016-02-02
modified2002-02-08
published2002-02-08
reporterTamer Sahin
sourcehttps://www.exploit-db.com/download/21285/
titleHP AdvanceStack Switch Authentication Bypass Vulnerability