Vulnerabilities > CVE-2002-1147 - Denial Of Service vulnerability in HP Procurve 4000M Switch Device Reset

047910
CVSS 7.1 - HIGH
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
COMPLETE
network
hp
exploit available

Summary

The HTTP administration interface for HP Procurve 4000M Switch firmware before C.09.16, with stacking features and remote administration enabled, does not authenticate requests to reset the device, which allows remote attackers to cause a denial of service via a direct request to the device_reset CGI program. Successful exploitation requires that stacking features and remote administration are enabled.

Exploit-Db

descriptionHP Procurve 4000M Switch Device Reset Denial Of Service Vulnerability. CVE-2002-1147. Dos exploit for hardware platform
idEDB-ID:21828
last seen2016-02-02
modified2002-09-24
published2002-09-24
reporterBrook Powers
sourcehttps://www.exploit-db.com/download/21828/
titleHP Procurve 4000M Switch Device Reset Denial of Service Vulnerability