Vulnerabilities > CVE-2012-4362 - Credentials Management vulnerability in HP San/Iq 9.5

047910
CVSS 4.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
hp
CWE-255
exploit available

Summary

hydra.exe in HP SAN/iQ before 9.5 on the HP Virtual SAN Appliance has a hardcoded password of L0CAlu53R for the global$agent account, which allows remote attackers to obtain access to a management service via a login: request to TCP port 13838.

Vulnerable Configurations

Part Description Count
Application
Hp
1
Hardware
Hp
1

Common Weakness Enumeration (CWE)

Exploit-Db

  • descriptionHP VSA Remote Command Execution Exploit. CVE-2012-2986,CVE-2012-4361,CVE-2012-4362. Remote exploit for hardware platform
    fileexploits/hardware/remote/18893.py
    idEDB-ID:18893
    last seen2016-02-02
    modified2012-02-17
    platformhardware
    port
    published2012-02-17
    reporterNicolas Gregoire
    sourcehttps://www.exploit-db.com/download/18893/
    titleHP VSA Remote Command Execution Exploit
    typeremote
  • descriptionHP StorageWorks P4000 Virtual SAN Appliance Command Execution. CVE-2012-2986,CVE-2012-4361,CVE-2012-4362. Remote exploit for hardware platform
    fileexploits/hardware/remote/18901.rb
    idEDB-ID:18901
    last seen2016-02-02
    modified2012-05-21
    platformhardware
    port
    published2012-05-21
    reportermetasploit
    sourcehttps://www.exploit-db.com/download/18901/
    titleHP StorageWorks P4000 Virtual SAN Appliance Command Execution
    typeremote