Check Point Reference: | CPAI-2013-2932 |
Date Published: | 27 Oct 2013 |
Severity: | Critical |
Last Updated: | Saturday 04 January, 2025 |
Source: | CVE-2013-2362 |
Protection Provided by: |
Security Gateway |
Who is Vulnerable? | HP System Management Homepage (SMH) prior to 7.2.1 |
Vulnerability Description | A stack buffer overflow exists in HP System Management Homepage. |
Vulnerability Details | The vulnerability is due to insufficient input validation when handling HTTP requests containing an iprange variable to the /proxy/DataValidation URI. A remote unauthenticated attacker could exploit this vulnerability by sending a crafted request to the vulnerable service. Successful exploitation could result in arbitrary code execution in the context of the currently affected service, which is System by default. |
This protection will detect and block attempts to exploit this vulnerability.
In order for the protection to be activated, update your product to the latest update. For information on how to update , go to SBP-2006-05, Protection tab and select the version of your choice.
SmartView Tracker will log the following entries:
Attack Name: HP Products Protection Violation
Attack Information: HP System Management Homepage iprange Stack Buffer Overflow