HP Smart Storage Administrator command injection
Added: 02/16/2017CVE: CVE-2016-8523
BID: 95868
Background
HP Smart Storage Administrator (HP SSA) is a web-based application that helps an administrator configure, manage, diagnose, and monitor HP ProLiant Smart Array Controllers and other storage devices such as host bus adapters (HBAs) and HP Storage controllers.Problem
A command injection vulnerability in HP Smart Storage Administrator allows remote attackers to execute arbitrary commands by sending a specially crafted query string in the URL of a GET request.Resolution
Update to HP Smart Storage Administrator v2.60.18.0 or later.References
http://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c05382349Limitations
Anonymous access must be enabled.Exploit requires the IO::Socket::SSL Perl module to be installed on the SAINTexploit host.
Platforms
LinuxBack to exploit index