CVE-2010-2705: Medium severity hp procurve switch software vulnerability
Published Aug 6, 2010
·Updated
Unspecified vulnerability on the HP ProCurve 1800-24G switch with software PB.03.02 and earlier, and the ProCurve 1800-8G switch with software PA.03.02 and earlier, when SNMP is enabled, allows remote attackers to obtain sensitive information via unknown vectors.
Affected Software
26 affected components
HP Procurve Switch Software<=pb.03.02
HP Procurve Switch Software=pb.02.01
HP Procurve Switch Software=pb.02.02
HP Procurve Switch Software=pb.02.03
HP Procurve Switch Software=pb.02.04
HP Procurve Switch Software=pb.02.05
HP Procurve Switch Software=pb.02.06
HP Procurve Switch Software=pb.02.07
HP Procurve Switch Software=pb.02.08
HP Procurve Switch Software=pb.02.09
HP Procurve Switch Software=pb.03.00
HP Procurve Switch Software=pb.03.01
HP Procurve Switch 1800-24g
HP Procurve Switch Software<=pa.03.02
HP Procurve Switch Software=pa.02.01
HP Procurve Switch Software=pa.02.02
HP Procurve Switch Software=pa.02.03
HP Procurve Switch Software=pa.02.04
HP Procurve Switch Software=pa.02.05
HP Procurve Switch Software=pa.02.06
HP Procurve Switch Software=pa.02.07
HP Procurve Switch Software=pa.02.08
HP Procurve Switch Software=pa.02.09
HP Procurve Switch Software=pa.03.00
HP Procurve Switch Software=pa.03.01
HP Procurve Switch 1800-8g
Event History
Aug 6, 2010
CVE Published
via MITRE·07:31 PM
Data Sourced
via MITRE·07:31 PM
Description
Aug 9, 2010
Data Sourced
11:58 AM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-2705?
CVE-2010-2705 has been classified as a moderate severity vulnerability.
2
How do I fix CVE-2010-2705?
To fix CVE-2010-2705, upgrade your HP ProCurve switch to a version later than PB.03.02 for the 1800-24G switch or PA.03.02 for the 1800-8G switch.
3
What types of devices are affected by CVE-2010-2705?
CVE-2010-2705 affects the HP ProCurve 1800-24G and 1800-8G switches with specific software versions.
4
What can attackers exploit in CVE-2010-2705?
Attackers can exploit CVE-2010-2705 to obtain sensitive information when SNMP is enabled on the affected devices.
5
When was CVE-2010-2705 disclosed?
CVE-2010-2705 was disclosed in July 2010.