Lucene search

K
certCERTVU:119952
HistoryJan 31, 2001 - 12:00 a.m.

HP-UX Support Tools Manager vulnerable to denial of service

2001-01-3100:00:00
www.kb.cert.org
22

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

EPSS

0

Percentile

5.1%

Overview

There is a vulnerability in the Hewlett-Packard Support Tools Manager that allows a local user to create a denial-of-service condition.

Description

The Hewlett-Packard Support Tools is a collection of diagnostic tools that allow operators of HP-UX systems to test and diagnose hardware configurations. On January 18, 2001, HP announced a vulnerability in the HP Support Tools Manager product that allows a local user to create a denial-of-service condition. This vulnerability is reported to affect HP9000 Series 700 and 800 systems running HP-UX versions 11.11, 11.00, and 10.20.


Impact

According to HP’s report, successful exploitation of this vulnerability could result in a denial-of-service attack.


Solution

HP has provided patches for each of the affected versions; please see the vendor section of this document for further details.


Vendor Information

119952

Filter by status: All Affected Not Affected Unknown

Filter by content: __ Additional information available

__ Sort by: Status Alphabetical

Expand all

Javascript is disabled. Click here to view vendors.

Hewlett Packard __ Affected

Updated: March 22, 2001

Status

Affected

Vendor Statement

To view the HP Security Bulletin, please visit <http://itrc.hp.com> and search for “HPSBUX0101-137”. Please note that registration may be required to access this document.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

The CERT/CC has no additional comments at this time.

If you have feedback, comments, or additional information about this vulnerability, please send us [email](<mailto:[email protected]?Subject=VU%23119952 Feedback>).

CVSS Metrics

Group Score Vector
Base N/A N/A
Temporal N/A N/A
Environmental N/A

References

<http://www.securityfocus.com/bid/2239&gt;

Acknowledgements

This document was written by Jeffrey P. Lanza.

Other Information

CVE IDs: CVE-2001-0219
Severity Metric: 0.25 Date Public:

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

EPSS

0

Percentile

5.1%

Related for VU:119952