Overview
HP Insight Diagnostics 8.20 b2878 and possibly earlier versions contains multiple vulnerabilities.
Description
It has been reported that HP Insight Diagnostics 8.20 b2878 and possibly earlier versions contains multiple vulnerabilities that can be exploited by a remote attacker to execute arbitrary PHP code thus arbitrary commands with administrative privileges. CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') - CVE-2013-3573 |
Impact
By combining these vulnerabilities, an authenticated remote attacker may be able to execute arbitrary commands on the server with administrator privileges. |
Solution
We are currently unaware of a practical solution to this problem. |
Restrict Network Access |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 6.5 | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Temporal | 5 | E:U/RL:U/RC:UC |
Environmental | 1.2 | CDP:ND/TD:L/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to Markus Wulftange from Daimler TSS for reporting this vulnerability.
This document was written by Michael Orlando.
Other Information
CVE IDs: | CVE-2013-3573, CVE-2013-3574, CVE-2013-3575 |
Date Public: | 2013-06-10 |
Date First Published: | 2013-06-10 |
Date Last Updated: | 2014-07-30 06:35 UTC |
Document Revision: | 17 |