First published: Mon Aug 20 2012(Updated: )
hydra.exe in HP SAN/iQ before 9.5 on the HP Virtual SAN Appliance has a hardcoded password of L0CAlu53R for the global$agent account, which allows remote attackers to obtain access to a management service via a login: request to TCP port 13838.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HP SAN/iQ | =9.5 | |
HP Virtual SAN Appliance |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4362 has a high severity rating due to the presence of a hardcoded password allowing unauthorized access.
To address CVE-2012-4362, upgrade to HP SAN/iQ version 9.5 or later where the hardcoded password issue has been resolved.
CVE-2012-4362 affects users of HP SAN/iQ versions before 9.5 on the HP Virtual SAN Appliance.
The impact of CVE-2012-4362 includes potential unauthorized access to the management service of the affected devices.
Yes, CVE-2012-4362 can be exploited remotely since it allows attackers to access the management service via TCP port 13838.