U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search Results (Refine Search)

Search Parameters:
  • CPE Product Version: cpe:/a:hp:san%2fiq:8.1
There are 7 matching records.
Displaying matches 1 through 7.
Vuln ID Summary CVSS Severity
CVE-2013-2352

LeftHand OS (aka SAN iQ) 10.5 and earlier on HP StoreVirtual Storage devices does not provide a mechanism for disabling the HP Support challenge-response root-login feature, which makes it easier for remote attackers to obtain administrative access by leveraging knowledge of an unused one-time password.

Published: July 10, 2013; 6:55:00 PM -0400
V3.x:(not available)
V2.0: 9.4 HIGH
CVE-2012-3285

Unspecified vulnerability on the HP LeftHand Virtual SAN Appliance hydra with software before 10.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1513.

Published: February 06, 2013; 7:05:42 AM -0500
V3.x:(not available)
V2.0: 10.0 HIGH
CVE-2012-3284

Unspecified vulnerability on the HP LeftHand Virtual SAN Appliance hydra with software before 10.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1512.

Published: February 06, 2013; 7:05:42 AM -0500
V3.x:(not available)
V2.0: 10.0 HIGH
CVE-2012-3283

Unspecified vulnerability on the HP LeftHand Virtual SAN Appliance hydra with software before 10.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1511.

Published: February 06, 2013; 7:05:42 AM -0500
V3.x:(not available)
V2.0: 10.0 HIGH
CVE-2012-3282

Unspecified vulnerability on the HP LeftHand Virtual SAN Appliance hydra with software before 10.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1468.

Published: February 06, 2013; 7:05:42 AM -0500
V3.x:(not available)
V2.0: 10.0 HIGH
CVE-2012-4361

lhn/public/network/ping in HP SAN/iQ before 9.5 on the HP Virtual SAN Appliance allows remote authenticated users to execute arbitrary commands via shell metacharacters in the second parameter.

Published: August 20, 2012; 6:55:01 PM -0400
V3.x:(not available)
V2.0: 7.7 HIGH
CVE-2011-4157

Stack-based buffer overflow in hydra.exe in HP SAN/iQ before 9.5 on the HP StorageWorks P4000 Virtual SAN Appliance allows remote attackers to execute arbitrary code via a crafted login request.

Published: November 16, 2011; 11:55:00 AM -0500
V3.x:(not available)
V2.0: 10.0 HIGH