LeftHand OS (aka SAN iQ) 10.5 and earlier on HP StoreVirtual Storage devices does not provide a mechanism for disabling the HP Support challenge-response root-login feature, which makes it easier for remote attackers to obtain administrative access by leveraging knowledge of an unused one-time password.
2013-07-10T22:55:00.953
2025-04-11T00:51:21.963
Deferred
CVSSv2: 9.4 (HIGH)
AV:N/AC:L/Au:N/C:N/I:C/A:C
10.0
9.2
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | hp | san\/iq | ≤ 10.5 | Yes |
Application | hp | san\/iq | 8.0 | Yes |
Application | hp | san\/iq | 8.1 | Yes |
Application | hp | san\/iq | 8.5 | Yes |
Application | hp | san\/iq | 9.0 | Yes |
Application | hp | san\/iq | 9.5 | Yes |
Application | hp | san\/iq | 10.0 | Yes |
Hardware | dell | poweredge_2950 | * | No |
Hardware | hp | dl320s | * | No |
Hardware | hp | lefthand_nsm2060 | * | No |
Hardware | hp | lefthand_nsm2060_g2 | * | No |
Hardware | hp | lefthand_nsm2120_g2 | * | No |
Hardware | hp | lefthand_vsa | * | No |
Hardware | hp | p4000_vsa | * | No |
Hardware | hp | p4300 | * | No |
Hardware | hp | p4300_g2 | * | No |
Hardware | hp | p4500 | * | No |
Hardware | hp | p4500_g2 | * | No |
Hardware | hp | p4900_g2 | * | No |
Hardware | hp | storevirtual_4130 | * | No |
Hardware | hp | storevirtual_4330 | * | No |
Hardware | hp | storevirtual_4530 | * | No |
Hardware | hp | storevirtual_4630 | * | No |
Hardware | hp | storevirtual_4730 | * | No |
Hardware | hp | storevirtual_vsa | * | No |
Hardware | ibm | x3650 | * | No |