HP OneView Unspecified Remote Privilege Escalation (HPSBGN03034)

medium Nessus Plugin ID 76055

Synopsis

The remote host has an application installed that is affected by an unspecified, remote privilege escalation vulnerability.

Description

The version of HP OneView installed on the remote host is 1.0 or 1.01.
Such versions are potentially affected by an unspecified, remote privilege escalation vulnerability.

Solution

Upgrade to HP OneView 1.05 or later.

See Also

http://www.nessus.org/u?f1eddc86

https://seclists.org/bugtraq/2014/May/10

Plugin Details

Severity: Medium

ID: 76055

File Name: hp_oneview_privilege_escalation.nasl

Version: 1.7

Type: remote

Family: CGI abuses

Published: 6/13/2014

Updated: 1/19/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.5

CVSS v2

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 4.8

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS Score Source: CVE-2014-2602

Vulnerability Information

CPE: cpe:/a:hp:oneview

Required KB Items: www/hp_oneview

Exploit Ease: No known exploits are available

Patch Publication Date: 5/2/2014

Vulnerability Publication Date: 5/2/2014

Reference Information

CVE: CVE-2014-2602

BID: 67197

HP: emr_na-c04273152