Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Web configuration utility in HP AdvanceStack hubs J3200A through J3210A with firmware version A.03.07 and earlier, allows unauthorized users to bypass authentication via a direct HTTP request to the web_access.html file, which allows the user to change the switch's configuration and modify the administrator password.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
HP AdvanceStack Switch绕过管理认证漏洞
Vulnerability Description
HP AdvanceStack 10Base-T交换Hub组合了10Base-T功能和交换特性。 HP AdvanceStack 10Base-T交换Hub存在漏洞,一个非特权的用户可能绕过验证直接访问管理web页面。 由于没有限制未授权用户对"/security/web_access.html的访问",攻击者可以直接访问上述页面修改设备的超级用户口令,以及以管理员权限访问设备。另外,所有的验证信息将暴露给攻击者。
CVSS Information
N/A
Vulnerability Type
N/A