Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2018-7119

Quick assessment

Affected
HPE NonStop SAFEGAURD and NonStop H-series STDSEC-STANDARD SECURITY Product
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

HPE NonStop Safeguard是美国惠普企业公司(Hewlett Packard Enterprise,HPE)的一套具有容错功能的操作系统。 HPE NonStop Safeguard中存在安全漏洞,该漏洞源于NonStop Safeguard和NonStop Standard Security软件中的一些命令要求通过命令行参数传递用户名和密码。攻击者可利用该漏洞获取凭证。

AI Predicted 5.5 Difficulty: Moderate EPSS 0.32% · P24
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2018-7119

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
A Local Disclosure of Sensitive Information vulnerability was identified in HPE NonStop Safeguard earlier than version SPR T9750L01^AIC or T9750H05^AIH, and later versions when the PASSWORD-PROMPT configuration attribute is not set to BLIND; all versions on H-series. STDSEC-STANDARD SECURITY PROD All prior versions before T6533L01^ADU or T6533H05^ADW, and later versions when the PASSWORD-PROMPT configuration attribute is not set to BLIND and all versions on H-series . Note that some commands in NonStop Safeguard and NonStop Standard Security software require username and password to be passed as command line parameters, which may lead to a local disclosure of the credentials.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
HPE NonStop Safeguard 信任管理问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
HPE NonStop Safeguard是美国惠普企业公司(Hewlett Packard Enterprise,HPE)的一套具有容错功能的操作系统。 HPE NonStop Safeguard中存在安全漏洞,该漏洞源于NonStop Safeguard和NonStop Standard Security软件中的一些命令要求通过命令行参数传递用户名和密码。攻击者可利用该漏洞获取凭证。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
HPE NonStop SAFEGAURD and NonStop H-series STDSEC-STANDARD SECURITY Product SAFEGUARD All prior versions before SPR T9750L01^AIC or T9750H05^AIH -

II. Public POCs for CVE-2018-7119

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2018-7119

登录查看更多情报信息。

Other References for CVE-2018-7119 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2018-7119

No comments yet


Leave a comment