CVE-2002-1147

The HTTP administration interface for HP Procurve 4000M Switch firmware before C.09.16, with stacking features and remote administration enabled, does not authenticate requests to reset the device, which allows remote attackers to cause a denial of service via a direct request to the device_reset CGI program.
Configurations

Configuration 1 (hide)

cpe:2.3:h:hp:procurve_switch_4000m:*:*:*:*:*:*:*:*

History

20 Nov 2024, 23:40

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=103287951910420&w=2 - () http://marc.info/?l=bugtraq&m=103287951910420&w=2 -
References () http://online.securityfocus.com/advisories/4501 - Vendor Advisory () http://online.securityfocus.com/advisories/4501 - Vendor Advisory
References () http://www.iss.net/security_center/static/10172.php - Vendor Advisory () http://www.iss.net/security_center/static/10172.php - Vendor Advisory
References () http://www.securityfocus.com/bid/5784 - () http://www.securityfocus.com/bid/5784 -
References () http://www.tech-serve.com/research/advisories/2002/a092302-1.txt - () http://www.tech-serve.com/research/advisories/2002/a092302-1.txt -

Information

Published : 2002-10-11 04:00

Updated : 2024-11-20 23:40


NVD link : CVE-2002-1147

Mitre link : CVE-2002-1147

CVE.ORG link : CVE-2002-1147


JSON object : View

Products Affected

hp

  • procurve_switch_4000m