HP Multiple Network Products Remote Information Disclosure and DoS (HPSBHF02912)

high Nessus Plugin ID 71378

Synopsis

The remote host is missing a vendor-supplied software update.

Description

The remote HP router or switch could be missing a vendor-supplied update that corrects an issue that a malicious attacker could remotely exploit in order to cause a disclosure of information or denial of service (DoS).

Solution

Apply the vendor-specified update.

See Also

http://www.nessus.org/u?161f0c67

Plugin Details

Severity: High

ID: 71378

File Name: hp_procurve_HPSBHF02912.nasl

Version: 1.6

Type: combined

Family: Misc.

Published: 12/12/2013

Updated: 11/15/2018

Configuration: Enable paranoid mode

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.2

CVSS v2

Risk Factor: High

Base Score: 7

Temporal Score: 5.2

Vector: CVSS2#AV:N/AC:M/Au:S/C:P/I:N/A:C

Vulnerability Information

CPE: cpe:/h:hp:procurve_switch, cpe:/h:hp:3com_router, cpe:/h:hp:h3c_ethernet_switch

Required KB Items: Settings/ParanoidReport, Host/HP_Switch

Exploit Ease: No known exploits are available

Patch Publication Date: 8/8/2013

Vulnerability Publication Date: 8/8/2013

Reference Information

CVE: CVE-2013-4806

BID: 61691

CERT: 229804

HP: HPSBHF02912, SSRT101224, emr_na-c03880910