HP Onboard Administrator Multiple Vulnerabilities

high Nessus Plugin ID 70141

Synopsis

The remote web server is affected by multiple vulnerabilities.

Description

The remote web server is a version of HP Onboard Administrator (OA) that is affected by the following vulnerabilities :

- HP Onboard Administrator before 3.50 allows remote attackers to obtain sensitive information via unspecified vectors. (CVE-2012-0130)

- HP Onboard Administrator before 3.50 allows remote attackers to bypass intended access restrictions and execute arbitrary code via unspecified vectors.
(CVE-2012-0129)

- HP Onboard Administrator before 3.50 allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks via unspecified vectors.
(CVE-2012-0128)

Solution

Upgrade to HP Onboard Administrator 3.50 or later.

See Also

http://www.nessus.org/u?a9794c7b

http://www.nessus.org/u?b4ced97c

Plugin Details

Severity: High

ID: 70141

File Name: hp_onboard_admin_3_50.nasl

Version: 1.6

Type: remote

Family: CGI abuses

Published: 9/26/2013

Updated: 1/19/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 7.6

Temporal Score: 6.3

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/a:hp:onboard_administrator

Required KB Items: Host/HP/Onboard_Administrator

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 4/2/2013

Vulnerability Publication Date: 4/2/2013

Reference Information

CVE: CVE-2012-0128, CVE-2012-0129, CVE-2012-0130

BID: 52862