CNCVE编号:CNCVE-20020065 CVE编号: 安全级别:中 漏洞中文描述: HP AdvanceStack 10Base-T交换Hub组合了10Base-T功能和交换特性。 HP AdvanceStack 11Base-T交换Hub存在漏洞,一个非特权的用户可能绕过验证直接访问管理web页面。由于没有限制未授权用户对“/security/web_access.html的访问”,攻击者可以直接访问上述页面修改设备的超级用户口令,以及以管理员权限访问设备。另外,所有的验证信息将暴露给攻击者。 漏洞英文描述: HP AdvanceStack 10Base-T Switching Hubs combine economical 10Base-T functionality with the performance of switching. Each switching hub starts out as a simple, single-segment, shared 10Base-T hub. A security vulnerability in the product allows attackers to bypass any authentication restrictions imposed on the configuration pages of the product. An attacker can get unauthorized access to the switch read/write password change page this page http://host/security/web_access.html and change superuser password. Connect superuser privileged via Web or Telnet. 漏洞参考: http://www.securityoffice.net/articles/hp/ 系统类型:其他 漏洞类型:权限有效性检查错误