Vulnerability Note VU#441363
HP Virtual SAN appliance root shell command injection
Overview
The HP Virtual SAN appliance version 9.5 is susceptible to a root shell command injection (CWE-77) vulnerability.
Description
Tenable Network Security has reported that HP's fix for the command injection vulnerability, EDB-ID 18893, was incomplete. The ping command for the appliance has a total of four parameters. The initial fix has only sanitized the input for one of the four parameters. Command injection is still possible against the other three parameters. |
Impact
An authenticated attacker can run arbitrary commands on the appliance. |
Solution
We are currently unaware of a practical solution to this problem. Please consider the following workarounds. |
Restrict access |
Vendor Information (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Hewlett-Packard Company | Affected | 10 Jul 2012 | 17 Aug 2012 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | 7.7 | AV:A/AC:L/Au:S/C:C/I:C/A:C |
| Temporal | 6.2 | E:POC/RL:U/RC:UC |
| Environmental | 6.2 | CDP:ND/TD:ND/CR:ND/IR:ND/AR:ND |
References
Credit
Thanks to Tenable Network Security for reporting this vulnerability.
This document was written by Jared Allar.
Other Information
- CVE IDs: CVE-2012-2986
- Date Public: 17 Aug 2012
- Date First Published: 17 Aug 2012
- Date Last Updated: 17 Aug 2012
- Document Revision: 15
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.