Vulnerabilities > CVE-2010-4115 - Credentials Management vulnerability in HP Storageworks Modular Smart Array P2000 G3 Firmware
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
HP StorageWorks Modular Smart Array P2000 G3 firmware TS100R011, TS100R025, TS100P002, TS200R005, TS201R014, and TS201R015 installs an undocumented admin account with a default "!admin" password, which allows remote attackers to gain privileges.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Nessus
NASL family | Gain a shell remotely |
NASL id | HP_STORAGEWORKS_ADMIN_DEFAULT_CREDS.NASL |
description | The remote device appears to be a HP StorageWorks MSA P2000 series. There is a hidden, undocumented account named |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 51369 |
published | 2010-12-23 |
reporter | This script is Copyright (C) 2010-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/51369 |
title | HP StorageWorks MSA P2000 Hidden 'admin' User Default Credentials |
References
- http://archives.neohapsis.com/archives/bugtraq/2010-12/0104.html
- http://archives.neohapsis.com/archives/bugtraq/2010-12/0104.html
- http://marc.info/?l=bugtraq&m=129251637904727&w=2
- http://marc.info/?l=bugtraq&m=129251637904727&w=2
- http://marc.info/?l=bugtraq&m=129251637904727&w=2
- http://marc.info/?l=bugtraq&m=129251637904727&w=2
- http://secunia.com/advisories/42583
- http://secunia.com/advisories/42583
- http://www.securityfocus.com/archive/1/515196/100/0/threaded
- http://www.securityfocus.com/archive/1/515196/100/0/threaded
- http://www.securityfocus.com/archive/1/515251/100/0/threaded
- http://www.securityfocus.com/archive/1/515251/100/0/threaded
- http://www.securityfocus.com/archive/1/515262/100/0/threaded
- http://www.securityfocus.com/archive/1/515262/100/0/threaded
- http://www.securityfocus.com/bid/45386
- http://www.securityfocus.com/bid/45386
- http://www.securitytracker.com/id?1024904
- http://www.securitytracker.com/id?1024904
- http://www.vupen.com/english/advisories/2010/3250
- http://www.vupen.com/english/advisories/2010/3250
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64125
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64125