ZDI-CAN-21510: ZDI-23-1402: Hewlett Packard Enterprise OneView resetAdminPassword Authentication Bypass Vulnerability
This vulnerability allows remote attackers to bypass authentication on affected installations of Hewlett Packard Enterprise OneView. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2023-30908.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-21510?
ZDI-CAN-21510 has a CVSS rating of 9.8, indicating a critical severity level.
How do I fix ZDI-CAN-21510?
To fix ZDI-CAN-21510, apply the latest security patches provided by Hewlett Packard Enterprise for OneView.
What type of attack vectors are associated with ZDI-CAN-21510?
ZDI-CAN-21510 allows remote attackers to bypass authentication, making unauthorized access possible.
Are there any authentication requirements for exploiting ZDI-CAN-21510?
No authentication is required to exploit ZDI-CAN-21510, allowing for easy exploitation by attackers.
What vulnerabilities are related to ZDI-CAN-21510?
ZDI-CAN-21510 is associated with CVE-2023-3090, which details the vulnerability in HPE OneView.