CVE-2014-2603: Low severity HP Hp H-series Fibre Channel Switch Firmware vulnerability

Published May 10, 2014
·
Updated

Unspecified vulnerability on HP 8/20q switches, SN6000 switches, and 8Gb Simple SAN Connection Kit with firmware before 8.0.14.08.00 allows remote authenticated users to obtain sensitive information via unknown vectors.

Affected Software

26 affected components
HP Hp H-series Fibre Channel Switch Firmware<=8.0
HP 8\/20q Fibre Channel Switch 16 Port=ak242a
HP 8\/20q Fibre Channel Switch 16 Port=ak242b
HP 8\/20q Fibre Channel Switch 8 Port=aq233a
HP 8\/20q Fibre Channel Switch 8 Port=aq233b
HP 8Gb Simple SAN Connection Kit=ak241a
HP 8Gb Simple SAN Connection Kit=ak241b
HP Sn6000 Stackable 8gb 12-port Single Power Fibre Channel Switch=bk780a
HP Sn6000 Stackable 8gb 12-port Single Power Fibre Channel Switch=bk780b
HP Sn6000 Stackable 8gb 24-port Dual Power Fibre Channel Switch=aw576a
HP Sn6000 Stackable 8gb 24-port Dual Power Fibre Channel Switch=aw576b
HP Sn6000 Stackable 8gb 24-port Single Power Fibre Channel Switch=aw575a
HP Sn6000 Stackable 8gb 24-port Single Power Fibre Channel Switch=aw575b
All of the following
HP Hp H-series Fibre Channel Switch Firmware<=8.0
Any of the following
HP 8\/20q Fibre Channel Switch 16 Port=ak242a
HP 8\/20q Fibre Channel Switch 16 Port=ak242b
HP 8\/20q Fibre Channel Switch 8 Port=aq233a
HP 8\/20q Fibre Channel Switch 8 Port=aq233b
HP 8Gb Simple SAN Connection Kit=ak241a
HP 8Gb Simple SAN Connection Kit=ak241b
HP Sn6000 Stackable 8gb 12-port Single Power Fibre Channel Switch=bk780a
HP Sn6000 Stackable 8gb 12-port Single Power Fibre Channel Switch=bk780b
HP Sn6000 Stackable 8gb 24-port Dual Power Fibre Channel Switch=aw576a
HP Sn6000 Stackable 8gb 24-port Dual Power Fibre Channel Switch=aw576b
HP Sn6000 Stackable 8gb 24-port Single Power Fibre Channel Switch=aw575a
HP Sn6000 Stackable 8gb 24-port Single Power Fibre Channel Switch=aw575b

Event History

May 10, 2014
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Data Sourced
via NVD·01:55 AM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2014-2603?

CVE-2014-2603 is considered a medium severity vulnerability due to potential exposure of sensitive information.

2

How do I fix CVE-2014-2603?

To fix CVE-2014-2603, upgrade the firmware to version 8.0.14.08.00 or later.

3

Who is affected by CVE-2014-2603?

CVE-2014-2603 affects HP 8/20q switches, SN6000 switches, and the 8Gb Simple SAN Connection Kit with specific firmware versions.

4

What kind of information can be exposed due to CVE-2014-2603?

CVE-2014-2603 allows remote authenticated users to potentially access sensitive information, the specifics of which are not disclosed.

5

Is there a workaround for CVE-2014-2603?

There are no documented workarounds for CVE-2014-2603; the only mitigation is to update the firmware.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203