HP-UX PHSS_42328 : s700_800 11.X OV NNM9.00 NNM 9.0x Patch 5

High Nessus Plugin ID 56849

Synopsis

The remote HP-UX host is missing a security-related patch.

Description

s700_800 11.X OV NNM9.00 NNM 9.0x Patch 5 :

The remote HP-UX host is affected by multiple vulnerabilities :

- Apotential security vulnerability has been identified with HP Network Node Manager I (NNMi) on HP-UX, Linux, Solaris, and Windows. The vulnerability could be remotely exploited resulting in unauthorized access.
References: CVE-2013-2351 (SSRT101012, ZDI-CAN-1566).

- A potential security vulnerability has been identified with HP Network Node Manager i (NNMi) for HP-UX, Linux, Solaris, and Windows. The vulnerability could be remotely exploited resulting in unauthorized disclosure of information. (HPSBMU02714 SSRT100244)

- Potential security vulnerabilities have been identified with HP Network Node Manager i (NNMi) for HP-UX, Linux, Solaris, and Windows. The vulnerabilities could be remotely exploited resulting in cross site scripting (XSS). (HPSBMU02708 SSRT100633)

- A potential vulnerability has been identified with HP Network Node Manager i (NNMi) for HP-UX, Linux, Solaris, and Windows. The vulnerability could be remotely exploited resulting in unauthorized access to NNMi processes. (HPSBMA02659 SSRT100440)

Solution

Install patch PHSS_42328 or subsequent.

See Also

http://www.nessus.org/u?7dec283b

http://www.nessus.org/u?8792dae1

http://www.nessus.org/u?85d28e00

http://www.nessus.org/u?54da22c0

Plugin Details

Severity: High

ID: 56849

File Name: hpux_PHSS_42328.nasl

Version: 1.24

Type: local

Published: 2012/03/06

Modified: 2018/07/12

Dependencies: 12634

Risk Information

Risk Factor: High

CVSSv2

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:H/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/o:hp:hp-ux

Required KB Items: Host/local_checks_enabled, Host/HP-UX/version, Host/HP-UX/swlist

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2011/11/03

Exploitable With

CANVAS (CANVAS)

Core Impact

Metasploit (JBoss JMX Console Deployer Upload and Execute)

ExploitHub (EH-12-132)

Reference Information

CVE: CVE-2010-0738, CVE-2011-1534, CVE-2011-4155, CVE-2011-4156, CVE-2013-2351

BID: 47420, 50635, 61132

HP: emr_na-c02788734, emr_na-c03035744, emr_na-c03057508, emr_na-c03747342, SSRT100244, SSRT100440, SSRT100633

IAVB: 2013-B-0073