HP Lefthand Virtual SAN Appliance Server Diag Request Buffer Overflow

Strike ID:
E13-5i001
CVSS:
10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C)
False Positive:
f
Variants:
1
Year:
2013

Description

This strike exploits an information disclosure vulnerability in HP Lefthand's Appliance Server. The vulnerability is to due a design weakness within the hydra component that processes snapshot requests. The server will respond to form2 requests with important system information, including hashed used passwords, regardless of the source of the request. A remote attacker could exploit this vulnerability to compromise user credentials and log into the server using administrative credentials.

CVE