[NEWS] Hewlett Packard AdvanceStack Switch Management Authentication Bypass Vulnerability

From: support@securiteam.com
Date: 02/11/02


From: support@securiteam.com
To: list@securiteam.com
Date: Mon, 11 Feb 2002 19:47:12 +0100 (CET)

The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

When was the last time you checked your server's security?
How about a monthly report?
http://www.AutomatedScanning.com - Know that you're safe.
- - - - - - - - -

  Hewlett Packard AdvanceStack Switch Management Authentication Bypass
Vulnerability
------------------------------------------------------------------------

SUMMARY

HP <http://www.hp.com/rnd/support/manuals/> AdvanceStack 10Base-T
Switching Hubs combine economical 10Base-T functionality with the
performance of switching. Each switching hub starts out as a simple,
single-segment, shared 10Base-T hub. A security vulnerability in the
product allows attackers to bypass any authentication restrictions imposed
on the configuration pages of the product.

DETAILS

Vulnerable systems:
HP J3210A AdvanceStack

A problem with the HP switch allows some users to change configuration of
the switch. A bug introduced in the HP AdvanceStack J3210A that could
allow users full access on the switch. Upon taking advantage of this
vulnerability, the user could change the configuration of the switch and
could change admin password.

Therefore, it is possible for a superuser password changing with
unprivileged access on the switch to gain elevated privileges, and
potentially change configuration of the switch.

Exploit:
An attacker can get unauthorized access to the switch read/write password
change page this page http://host/security/web_access.html and change
superuser password. Connect superuser privileged via Web or Telnet.

ADDITIONAL INFORMATION

The information has been provided by <mailto:ts@securityoffice.net> Tamer
Sahin.

========================================

This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.



Relevant Pages

  • Summary of Microsoft compiler flaw discussions
    ... Cigital implied that Microsoft touted this new switch as a panacea to ... No "flaw" exists in Microsoft's new compiler. ... sense of security because it is easily defeated." ... attacks against code compiled with the new compiler. ...
    (NT-Bugtraq)
  • Re: National Security Backdoor in telnetd - all versions.
    ... > within the National Security field? ... >>sniffed when you have to reconfigure your switch from offsite. ... not government. ... The vendors themselves have been screaming about the export ...
    (comp.os.linux.security)
  • Re: Transport Mode IPSEC
    ... security with environment security. ... NFS server with an arp cache poison, ... If you correct the environment security, ... For example, you put in a decent managed switch, you ...
    (freebsd-questions)
  • RE: Rogue IP Address
    ... capability that you paid for when buying the switch, ... someone will holler about his network not working. ... prospectus based upon the core principle concepts of security. ... This ALL INCLUSIVE curriculum utilizes lectures, case studies and true hands-on utilization ...
    (Security-Basics)
  • FW: [Full-Disclosure] HP Full Disclosure Story (fwd)
    ... up Dan Grove's and the rest of your so called security teams collective ... > vulnerability affected 8 different swicth models. ... Hewlett Packard AdvanceStack Switch Managment Authentication Bypass ... I'm sorry to see the threatening tone in your message. ...
    (Full-Disclosure)