HP System Management Homepage < 7.2.1.0 Multiple Vulnerabilities (BEAST)

This script is Copyright (C) 2013-2015 Tenable Network Security, Inc.


Synopsis :

The remote web server is affected by multiple vulnerabilities.

Description :

According to the web server's banner, the version of HP System
Management Homepage (SMH) hosted on the remote web server is a version
prior to 7.2.1.0. It is, therefore, affected by the following
vulnerabilities :

- An information disclosure vulnerability, known as BEAST,
exists in the SSL 3.0 and TLS 1.0 protocols due to a
flaw in the way the initialization vector (IV) is
selected when operating in cipher-block chaining (CBC)
modes. A man-in-the-middle attacker can exploit this
to obtain plaintext HTTP header data, by using a
blockwise chosen-boundary attack (BCBA) on an HTTPS
session, in conjunction with JavaScript code that uses
the HTML5 WebSocket API, the Java URLConnection API,
or the Silverlight WebClient API. (CVE-2011-3389)

- The utility 'apachectl' can receive a zero-length
directory name in the LD_LIBRARY_PATH via the 'envvars'
file. A local attacker with access to that utility
could exploit this to load a malicious Dynamic Shared
Object (DSO), leading to arbitrary code execution.
(CVE-2012-0883)

- Numerous, unspecified errors could allow remote denial
of service attacks. (CVE-2012-2110, CVE-2012-2329,
CVE-2012-2336, CVE-2013-2357, CVE-2013-2358,
CVE-2013-2359, CVE-2013-2360)

- The fix for CVE-2012-1823 does not completely correct
the CGI query parameter vulnerability. Disclosure of
PHP source code and code execution are still possible.
Note that this vulnerability is exploitable only when
PHP is used in CGI-based configurations. Apache with
'mod_php' is not an exploitable configuration.
(CVE-2012-2311, CVE-2012-2335)

- Unspecified errors exist that could allow unauthorized
access. (CVE-2012-5217, CVE-2013-2355)

- Unspecified errors exist that could allow disclosure of
sensitive information. (CVE-2013-2356, CVE-2013-2363)

- An unspecified error exists that could allow cross-site
scripting attacks. (CVE-2013-2361)

- Unspecified errors exist that could allow a local
attacker to cause denial of service conditions.
(CVE-2013-2362, CVE-2013-2364)

- An as-yet unspecified vulnerability exists that could
cause a denial of service condition. (CVE-2013-4821)

See also :

http://www.zerodayinitiative.com/advisories/ZDI-13-204/
http://www.nessus.org/u?647212eb
http://www.nessus.org/u?5e861a23
http://www.securityfocus.com/archive/1/528723/30/0/threaded
https://www.imperialviolet.org/2011/09/23/chromeandbeast.html
https://www.openssl.org/~bodo/tls-cbc.txt

Solution :

Upgrade to HP System Management Homepage 7.2.1.0 or later.

Risk factor :

High / CVSS Base Score : 7.8
(CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N)
CVSS Temporal Score : 6.1
(CVSS2#E:POC/RL:OF/RC:C)
Public Exploit Available : true