HP-UX PHSS_42328 : s700_800 11.X OV NNM9.00 NNM 9.0x Patch 5

high Nessus Plugin ID 56849

Synopsis

The remote HP-UX host is missing a security-related patch.

Description

s700_800 11.X OV NNM9.00 NNM 9.0x Patch 5 :

The remote HP-UX host is affected by multiple vulnerabilities :

- Apotential security vulnerability has been identified with HP Network Node Manager I (NNMi) on HP-UX, Linux, Solaris, and Windows. The vulnerability could be remotely exploited resulting in unauthorized access.
References: CVE-2013-2351 (SSRT101012, ZDI-CAN-1566).

- A potential security vulnerability has been identified with HP Network Node Manager i (NNMi) for HP-UX, Linux, Solaris, and Windows. The vulnerability could be remotely exploited resulting in unauthorized disclosure of information. (HPSBMU02714 SSRT100244)

- Potential security vulnerabilities have been identified with HP Network Node Manager i (NNMi) for HP-UX, Linux, Solaris, and Windows. The vulnerabilities could be remotely exploited resulting in cross site scripting (XSS). (HPSBMU02708 SSRT100633)

- A potential vulnerability has been identified with HP Network Node Manager i (NNMi) for HP-UX, Linux, Solaris, and Windows. The vulnerability could be remotely exploited resulting in unauthorized access to NNMi processes. (HPSBMA02659 SSRT100440)

Solution

Install patch PHSS_42328 or subsequent.

See Also

http://www.nessus.org/u?7dec283b

http://www.nessus.org/u?8792dae1

http://www.nessus.org/u?85d28e00

http://www.nessus.org/u?54da22c0

Plugin Details

Severity: High

ID: 56849

File Name: hpux_PHSS_42328.nasl

Version: 1.26

Type: local

Published: 3/6/2012

Updated: 5/25/2022

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.3

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: cpe:/o:hp:hp-ux

Required KB Items: Host/local_checks_enabled, Host/HP-UX/version, Host/HP-UX/swlist

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 11/3/2011

CISA Known Exploited Vulnerability Due Dates: 6/15/2022

Exploitable With

CANVAS (CANVAS)

Core Impact

Metasploit (JBoss JMX Console Deployer Upload and Execute)

ExploitHub (EH-12-132)

Reference Information

CVE: CVE-2010-0738, CVE-2011-1534, CVE-2011-4155, CVE-2011-4156, CVE-2013-2351

BID: 47420, 50635, 61132

HP: SSRT100244, SSRT100440, SSRT100633, emr_na-c02788734, emr_na-c03035744, emr_na-c03057508, emr_na-c03747342

IAVB: 2013-B-0073