First published: Wed Nov 16 2011(Updated: )
Stack-based buffer overflow in hydra.exe in HP SAN/iQ before 9.5 on the HP StorageWorks P4000 Virtual SAN Appliance allows remote attackers to execute arbitrary code via a crafted login request.
Credit: hp-security-alert@hp.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hp Centralized Management Console Software | <=9.0 | |
Hp Centralized Management Console Software | =7.0.01-sp1 | |
Hp Centralized Management Console Software | =8.0 | |
Hp Centralized Management Console Software | =8.1 | |
Hp Centralized Management Console Software | =8.5 | |
HP SAN/iQ | <=9.0 | |
HP SAN/iQ | =8.0 | |
HP SAN/iQ | =8.1 | |
HP SAN/iQ | =8.5 | |
HP LeftHand Virtual SAN Appliance |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4157 is considered critical due to the potential for remote code execution.
To fix CVE-2011-4157, upgrade to HP SAN/iQ version 9.5 or later.
CVE-2011-4157 affects HP SAN/iQ versions up to 9.0 and several versions of HP Centralized Management Console Software.
Yes, CVE-2011-4157 can be exploited by remote attackers through a crafted login request.
In CVE-2011-4157, a stack-based buffer overflow allows attackers to overwrite program memory, potentially leading to arbitrary code execution.