Vulnerabilities > CVE-2017-5813 - Unspecified vulnerability in HP Network Automation
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
LOW Availability impact
LOW Summary
A remote unauthenticated access vulnerability in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found.
Vulnerable Configurations
Nessus
NASL family | CGI abuses |
NASL id | HP_NETWORK_AUTOMATION_HPSBGN03740.NASL |
description | The HP Network Automation application running on the remote host is version 9.1x, 9.2x, or 10.00.x prior to 10.00.022; 10.10.x or 10.11.x prior to 10.11.03; or 10.20.x prior to 10.21.01. It is, therefore, affected by multiple vulnerabilities : - A SQL injection vulnerability exists in the RedirectServlet component due to improper sanitization of user-supplied input. An unauthenticated, remote attacker can exploit this to inject or manipulate SQL queries in the back-end database, resulting in the manipulation or disclosure of arbitrary data. (CVE-2017-5810) - An information disclosure vulnerability exists in the TrueControl Management Engine service due a path traversal flaw caused by improper sanitization of user-supplied input. An unauthenticated, remote attacker can exploit this, via a specially created request, to read arbitrary files. (CVE-2017-5811) - An authentication bypass vulnerability exists in the PermissionFilter class due to a path traversal flaw caused by improper sanitization of user-supplied input. An unauthenticated, remote attacker can exploit this, via a specially crafted request, to bypass authentication and gain access to an associated servlet. (CVE-2017-5812) - An unspecified flaw exists that allows an unauthenticated, remote attacker to bypass security controls and gain unauthorized access. (CVE-2017-5813) - An unspecified flaw exists that allows an unauthenticated, remote attacker to bypass authentication checks. (CVE-2017-5814) |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 100159 |
published | 2017-05-12 |
reporter | This script is Copyright (C) 2017-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/100159 |
title | HP Network Automation 9.x, 10.x < 10.00.022 / 10.1x.x < 10.11.03 / 10.20.x < 10.21.01 Multiple Vulnerabilities |
code |
|
References
- http://www.securityfocus.com/bid/98331
- http://www.securityfocus.com/bid/98331
- http://www.securitytracker.com/id/1038407
- http://www.securitytracker.com/id/1038407
- https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbgn03740en_us
- https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbgn03740en_us