Overview
The HP Data Protector does not perform user authentication, even when Encrypted Control Communications is enabled, and contains an embedded SSL private key that is shared among all installations.
Description
CWE-306: Missing Authentication for Critical Function - CVE-2016-2004 Data Protector does not authenticate users, even with Encrypted Control Communications enabled. An unauthenticated remote attacker may be able to execute code on the server hosting Data Protector. |
Impact
An unauthenticated remote attacker may be able to execute code on the server, or perform man-in-the-middle attacks against the server. |
Solution
Apply an update |
Restrict Network Access |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 9.3 | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Temporal | 8.4 | E:POC/RL:U/RC:C |
Environmental | 6.3 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to Ian Lovering for reporting this vulnerability.
This document was written by Garret Wassermann.
Other Information
CVE IDs: | CVE-2016-2004 |
Date Public: | 2016-04-18 |
Date First Published: | 2016-04-22 |
Date Last Updated: | 2016-04-22 16:56 UTC |
Document Revision: | 38 |