First published: Mon Aug 20 2012(Updated: )
lhn/public/network/ping in HP SAN/iQ before 9.5 on the HP Virtual SAN Appliance allows remote authenticated users to execute arbitrary commands via shell metacharacters in the second parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HP SAN/iQ | <=9.0 | |
HP SAN/iQ | =8.0 | |
HP SAN/iQ | =8.1 | |
HP SAN/iQ | =8.5 | |
HP Virtual SAN Appliance |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4361 is considered a high severity vulnerability that allows remote authenticated users to execute arbitrary commands.
To fix CVE-2012-4361, upgrade HP SAN/iQ software to version 9.5 or later.
CVE-2012-4361 affects users of HP SAN/iQ versions prior to 9.5 and specific versions 8.0, 8.1, and 8.5.
No, CVE-2012-4361 requires the attacker to be a remote authenticated user.
CVE-2012-4361 can be exploited to execute arbitrary commands through shell metacharacters.