ID

VAR-200206-0050


CVE

CVE-2002-0350


TITLE

HP ProCurve Switch Denial of Service Vulnerability

Trust: 0.9

sources: BID: 4212 // CNNVD: CNNVD-200206-071

DESCRIPTION

HP Procurve Switch 4000M running firmware C.08.22 and C.09.09 allows remote attackers to cause a denial of service via a port scan of the management IP address, which disables the telnet service. A problem with the switch could make it possible to deny telnet service to legitimate users of the device. The problem is in the handling of port scans by the device. A ProCurve switch could be led to deny telnet users service of the switch. When the switch is portscanned by a tool such as nmap, which is capable of producing a high amount of TCP connect() requests in a short period of time, the switch will no longer accept new telnet connections. Reportedly, this issue does not affect ICMP or SNMP management of the device, nor are existing telnet sessions disconnected. Rebooting the switch may be required in order to regain normal functionality. HP ProCurve 4000M with firmware version C.09.09 or C.08.22 are reported to be susceptible to this issue. HP ProCurve Switch is a switch product produced by HP

Trust: 1.26

sources: NVD: CVE-2002-0350 // BID: 4212 // VULHUB: VHN-4743

AFFECTED PRODUCTS

vendor:hpmodel:procurve switch 4000mscope:eqversion:c.09.09

Trust: 1.6

vendor:hpmodel:procurve switch 4000mscope:eqversion:c.08.22

Trust: 1.6

vendor:hpmodel:procurve switch 4000mscope: - version: -

Trust: 0.3

sources: BID: 4212 // CNNVD: CNNVD-200206-071 // NVD: CVE-2002-0350

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2002-0350
value: HIGH

Trust: 1.0

CNNVD: CNNVD-200206-071
value: HIGH

Trust: 0.6

VULHUB: VHN-4743
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2002-0350
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-4743
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-4743 // CNNVD: CNNVD-200206-071 // NVD: CVE-2002-0350

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2002-0350

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200206-071

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-200206-071

EXTERNAL IDS

db:NVDid:CVE-2002-0350

Trust: 2.0

db:BIDid:4212

Trust: 2.0

db:CNNVDid:CNNVD-200206-071

Trust: 0.7

db:BUGTRAQid:20020301 DOS ON HP PROCURVE 4000M SWITCH (POSSIBLY OTHERS)

Trust: 0.6

db:XFid:8329

Trust: 0.6

db:VULHUBid:VHN-4743

Trust: 0.1

sources: VULHUB: VHN-4743 // BID: 4212 // CNNVD: CNNVD-200206-071 // NVD: CVE-2002-0350

REFERENCES

url:http://www.securityfocus.com/bid/4212

Trust: 1.7

url:http://www.iss.net/security_center/static/8329.php

Trust: 1.7

url:http://marc.info/?l=bugtraq&m=101500123900612&w=2

Trust: 1.0

url:http://marc.theaimsgroup.com/?l=bugtraq&m=101500123900612&w=2

Trust: 0.6

url:http://www.hp.com/rnd/

Trust: 0.3

url:http://marc.info/?l=bugtraq&m=101500123900612&w=2

Trust: 0.1

sources: VULHUB: VHN-4743 // BID: 4212 // CNNVD: CNNVD-200206-071 // NVD: CVE-2002-0350

CREDITS

Jon Snyder※ jon@pdx.edu

Trust: 0.6

sources: CNNVD: CNNVD-200206-071

SOURCES

db:VULHUBid:VHN-4743
db:BIDid:4212
db:CNNVDid:CNNVD-200206-071
db:NVDid:CVE-2002-0350

LAST UPDATE DATE

2025-04-03T22:35:07.681000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-4743date:2016-10-18T00:00:00
db:BIDid:4212date:2009-07-11T10:56:00
db:CNNVDid:CNNVD-200206-071date:2007-05-07T00:00:00
db:NVDid:CVE-2002-0350date:2025-04-03T01:03:51.193

SOURCES RELEASE DATE

db:VULHUBid:VHN-4743date:2002-06-25T00:00:00
db:BIDid:4212date:2002-03-01T00:00:00
db:CNNVDid:CNNVD-200206-071date:2002-03-01T00:00:00
db:NVDid:CVE-2002-0350date:2002-06-25T04:00:00