Vulnerabilities > CVE-2013-2343 - Unspecified vulnerability in HP products
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Unspecified vulnerability on the HP LeftHand Virtual SAN Appliance hydra with software before 10.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1510.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |
Exploit-Db
description | HP StorageWorks P4000 Virtual SAN Appliance Login Buffer Overflow. CVE-2012-3282,CVE-2013-2343. Remote exploit for windows platform |
id | EDB-ID:27555 |
last seen | 2016-02-03 |
modified | 2013-08-13 |
published | 2013-08-13 |
reporter | metasploit |
source | https://www.exploit-db.com/download/27555/ |
title | HP StorageWorks P4000 Virtual SAN Appliance Login Buffer Overflow |
Metasploit
description | This module exploits a buffer overflow vulnerability found in HP's StorageWorks P4000 VSA on versions prior to 10.0. The vulnerability is due to an insecure usage of the sscanf() function when parsing login requests. This module has been tested successfully on the HP VSA 9 Virtual Appliance. |
id | MSF:EXPLOIT/LINUX/MISC/HP_VSA_LOGIN_BOF |
last seen | 2020-06-08 |
modified | 2017-07-24 |
published | 2013-08-10 |
references | |
reporter | Rapid7 |
source | https://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/linux/misc/hp_vsa_login_bof.rb |
title | HP StorageWorks P4000 Virtual SAN Appliance Login Buffer Overflow |
Nessus
NASL family | Gain a shell remotely |
NASL id | HP_VSA_10_0.NASL |
description | According to the version fingerprinted by Nessus, the remote host is an HP LeftHand Virtual SAN Appliance prior to version 10.0. It is, therefore, affected by multiple unspecified remote code execution vulnerabilities in the hydra service. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 64633 |
published | 2013-02-14 |
reporter | This script is Copyright (C) 2013-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/64633 |
title | HP LeftHand Virtual SAN Appliance < 10.0 hydra Service Multiple RCE |
code |
|
Packetstorm
data source | https://packetstormsecurity.com/files/download/122789/hp_vsa_login_bof.rb.txt |
id | PACKETSTORM:122789 |
last seen | 2016-12-05 |
published | 2013-08-12 |
reporter | juan vazquez |
source | https://packetstormsecurity.com/files/122789/HP-StorageWorks-P4000-Virtual-SAN-Appliance-Login-Buffer-Overflow.html |
title | HP StorageWorks P4000 Virtual SAN Appliance Login Buffer Overflow |
Saint
bid | 60884 |
description | HP LeftHand Virtual SAN Appliance Hydra Service Login Buffer Overflow |
osvdb | 94701 |
title | hp_lefthand_vsa_hydra_service_login |
type | remote |
References
- https://h20566.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03661318
- https://h20566.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03661318
- https://h20566.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03661318
- https://h20566.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03661318