Overview
HP Network Automation versions 9.0x, 9.1x, 9.2x, and 10.x contain multiple vulnerabilities affecting the administrative web interface.
Description
HP Network Automation versions 9.0x, 9.1x, 9.2x, and 10.x contain vulnerabilities in the administrative web interface, including multiple cross site request forgery (CSRF), cross-site scripting (XSS), and clickjacking issues. For more information, review the HP security bulletin. |
Impact
A remote, unauthenticated attacker may be able to trick an authenticated user into making an unintentional request to the web server that will be treated as an authentic request, leading to the possibility of privilege escalation, information leakage, code execution, or denial of service. |
Solution
Apply an update |
Vendor Information (Learn More)
Vendor | Status | Date Notified | Date Updated |
---|---|---|---|
Hewlett-Packard Company | Affected | 08 Dec 2014 | 16 Apr 2015 |
If you are a vendor and your product is affected, let us know.
CVSS Metrics (Learn More)
Group | Score | Vector |
---|---|---|
Base | 6.8 | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Temporal | 5.3 | E:POC/RL:OF/RC:C |
Environmental | 4.0 | CDP:N/TD:M/CR:ND/IR:ND/AR:ND |
References
- https://h20564.www2.hp.com/hpsc/doc/public/display?docId=emr_na-c04574207
- http://cwe.mitre.org/data/definitions/352.html
- http://cwe.mitre.org/data/definitions/79.html
- http://cwe.mitre.org/data/definitions/20.html
Credit
Thanks to Tim MalcomVetter of FishNet Security for reporting these vulnerabilities.
This document was written by Joel Land.
Other Information
- CVE IDs: CVE-2014-7886
- Date Public: 17 4월 2015
- Date First Published: 17 4월 2015
- Date Last Updated: 17 4월 2015
- Document Revision: 12
'취약점 정보1' 카테고리의 다른 글
Android 0-day vulnerability - Drive by download (0) | 2015.04.22 |
---|---|
CVE-2015-1097: Deobfuscating iOS Kernel Pointers With an IBM X-Force-Discovered Vulnerability (0) | 2015.04.22 |
Denial of Service Attacks Possible with OpenSSL Vulnerability CVE-2015-1787 (0) | 2015.04.19 |
Web 사이트를 OS마다 강제 종료시키는 공격 코드 확인 (MS15-034) (0) | 2015.04.19 |
Adobe 제품군 신규 취약점 보안 업데이트 권고 (0) | 2015.04.19 |