CVE-2013-2352
LeftHand OS (aka SAN iQ) 10.5 and earlier on HP StoreVirtual Storage devices does not provide a mechanism for disabling the HP Support challenge-response root-login feature, which makes it easier for remote attackers to obtain administrative access by leveraging knowledge of an unused one-time password.
Published:Jul 10, 2013
Last Modified:Apr 11, 2025
EPS:Jul 10, 2013
EPSS Score:0.02217
CVSS Score:9.4
Affected Products
Vendor
Product
Action
Vendor
Dell
Product
Poweredge 2950
Dell
Poweredge 2950
Vendor
Hp
Product
Dl320s
Hp
Dl320s
Vendor
Hp
Product
Lefthand Nsm2060
Hp
Lefthand Nsm2060
Vendor
Hp
Product
Lefthand Nsm2060 G2
Hp
Lefthand Nsm2060 G2
Vendor
Hp
Product
Lefthand Nsm2120 G2
Hp
Lefthand Nsm2120 G2
Vendor
Hp
Product
Lefthand Vsa
Hp
Lefthand Vsa
Vendor
Hp
Product
P4000 Vsa
Hp
P4000 Vsa
Vendor
Hp
Product
P4300
Hp
P4300
Vendor
Hp
Product
P4300 G2
Hp
P4300 G2
Vendor
Hp
Product
P4500
Hp
P4500
Vendor
Hp
Product
P4500 G2
Hp
P4500 G2
Vendor
Hp
Product
P4900 G2
Hp
P4900 G2
Vendor
Hp
Product
San\/iq
Hp
San\/iq
Vendor
Hp
Product
Storevirtual 4130
Hp
Storevirtual 4130
Vendor
Hp
Product
Storevirtual 4330
Hp
Storevirtual 4330
Vendor
Hp
Product
Storevirtual 4530
Hp
Storevirtual 4530
Vendor
Hp
Product
Storevirtual 4630
Hp
Storevirtual 4630
Vendor
Hp
Product
Storevirtual 4730
Hp
Storevirtual 4730
Vendor
Hp
Product
Storevirtual Vsa
Hp
Storevirtual Vsa
Vendor
Ibm
Product
X3650
Ibm
X3650
Exploits
No exploit reference
Common Weakness Enumeration
No CWE recorded yet
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
