ZDI-CAN-21806: ZDI-23-1599: Hewlett Packard Enterprise OneView Backup Hard-coded Cryptographic Key Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hewlett Packard Enterprise OneView. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2023-30912.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-21806?
ZDI-CAN-21806 has a high severity rating due to the ability of remote attackers to execute arbitrary code.
What systems are affected by ZDI-CAN-21806?
ZDI-CAN-21806 affects installations of Hewlett Packard Enterprise OneView.
How do I fix ZDI-CAN-21806?
To fix ZDI-CAN-21806, apply the relevant patches provided by Hewlett Packard Enterprise for OneView.
Can authentication be bypassed in ZDI-CAN-21806?
Yes, ZDI-CAN-21806 can be exploited even if authentication is required due to a bypass in the authentication mechanism.
What are the potential impacts of ZDI-CAN-21806?
The potential impacts of ZDI-CAN-21806 include unauthorized remote code execution on the affected systems.