ID

VAR-201303-0047


CVE

CVE-2012-5216


TITLE

HP ProCurve Switches Cross-Site Request Forgery Vulnerability

Trust: 0.8

sources: IVD: 0565d2e6-2353-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-02256

DESCRIPTION

Cross-site request forgery (CSRF) vulnerability on HP ProCurve 1700-8 (aka J9079A) switches with software before VA.02.09 and 1700-24 (aka J9080A) switches with software before VB.02.09 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. ProCurve 1700 series switches provided by Hewlett-Packard contain a cross-site request forgery vulnerability. Darren Willis of Fourteenforty Research Institute, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.If a user views a malicious page while logged in, product settings may be changed. ** Delete ** This case is based on early warning partnership JVN Vulnerability reports JVN#48108258 With the release of JVNDB-2013-000052 The contents have been moved to. JVNDB-2013-000052 Please refer to. The HP ProCurve Switch is a network switch developed by Hewlett-Packard. Exploiting this issue may allow a remote attacker to perform certain unauthorized actions. This may lead to further attacks. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Note: the current version of the following document is available here: https://h20566.www2.hp.com/portal/site/hpsc/public/kb/ docDisplay?docId=emr_na-c03699981 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c03699981 Version: 1 HPSBPV02855 SSRT100512 rev.1 - HP ProCurve 1700-8(J9079A) and 1700-24(J9080A) Switches, Cross Site Request Forgery (CSRF) NOTICE: The information in this Security Bulletin should be acted upon as soon as possible. Release Date: 2013-03-25 Last Updated: 2013-03-25 Potential Security Impact: Cross site request forgery (CSRF) Source: Hewlett-Packard Company, HP Software Security Response Team VULNERABILITY SUMMARY A potential security vulnerability has been identified with HP ProCurve 1700-8 (J9079A) and 1700-24 (J9080A) switches. References: CVE-2012-5216 (JVN#48108258) SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed. Product Name Product Number Impacted Software Versions HP ProCurve 1700-8 Switch J9079A VA.02.08 and earlier HP ProCurve 1700-24 Switch J9080A VB.02.08 and earlier BACKGROUND CVSS 2.0 Base Metrics =========================================================== Reference Base Vector Base Score CVE-2012-5216 (AV:N/AC:M/Au:N/C:P/I:P/A:P) 6.8 =========================================================== Information on CVSS is documented in HP Customer Notice: HPSN-2008-002 The Hewlett-Packard Company thanks JPCERT for reporting this vulnerability to security-alert@hp.com RESOLUTION HP has made the following software updates available to resolve the vulnerability. Support: For issues about implementing the recommendations of this Security Bulletin, contact normal HP Services support channel. For other issues about the content of this Security Bulletin, send e-mail to security-alert@hp.com. Report: To report a potential security vulnerability with any HP supported product, send Email to: security-alert@hp.com Subscribe: To initiate a subscription to receive future HP Security Bulletin alerts via Email: http://h41183.www4.hp.com/signup_alerts.php?jumpid=hpsc_secbulletins Security Bulletin List: A list of HP Security Bulletins, updated periodically, is contained in HP Security Notice HPSN-2011-001: https://h20566.www2.hp.com/portal/site/hpsc/public/kb/ docDisplay?docId=emr_na-c02964430 Security Bulletin Archive: A list of recently released Security Bulletins is available here: http://h20566.www2.hp.com/portal/site/hpsc/public/kb/secBullArchive/ Software Product Category: The Software Product Category is represented in the title by the two characters following HPSB. 3C = 3COM 3P = 3rd Party Software GN = HP General Software HF = HP Hardware and Firmware MP = MPE/iX MU = Multi-Platform Software NS = NonStop Servers OV = OpenVMS PI = Printing and Imaging PV = ProCurve ST = Storage Software TU = Tru64 UNIX UX = HP-UX Copyright 2013 Hewlett-Packard Development Company, L.P. Hewlett-Packard Company shall not be liable for technical or editorial errors or omissions contained herein. The information provided is provided "as is" without warranty of any kind. To the extent permitted by law, neither HP or its affiliates, subcontractors or suppliers will be liable for incidental,special or consequential damages including downtime cost; lost profits;damages relating to the procurement of substitute products or services; or damages for loss of data, or software restoration. The information in this document is subject to change without notice. Hewlett-Packard Company and the names of Hewlett-Packard products referenced herein are trademarks of Hewlett-Packard Company in the United States and other countries. Other product and company names mentioned herein may be trademarks of their respective owners. -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.19 (GNU/Linux) iEYEARECAAYFAlFQ05YACgkQ4B86/C0qfVkorACg9wWMUPZ7CBXrdqMKdMk84hEv HSAAn0R1TmKfcSoIcJb9MEy/Hg6EeJki =g9DB -----END PGP SIGNATURE-----

Trust: 3.51

sources: NVD: CVE-2012-5216 // JVNDB: JVNDB-2013-000052 // JVNDB: JVNDB-2013-002089 // CNVD: CNVD-2013-02256 // BID: 58701 // IVD: 0565d2e6-2353-11e6-abef-000c29c66e3d // VULHUB: VHN-58497 // PACKETSTORM: 120959

IOT TAXONOMY

category:['ICS', 'Network device']sub_category: -

Trust: 0.6

category:['ICS']sub_category: -

Trust: 0.2

sources: IVD: 0565d2e6-2353-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-02256

AFFECTED PRODUCTS

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.09

Trust: 1.6

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.38

Trust: 1.6

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.32

Trust: 1.6

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.36

Trust: 1.6

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.31

Trust: 1.6

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.35

Trust: 1.6

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.26

Trust: 1.6

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.39

Trust: 1.6

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.25

Trust: 1.6

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.37

Trust: 1.6

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.24

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.05

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.53

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:pa.03.00

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.23

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.34

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.52

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:pb.02.07

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.29

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.42

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:lteversion:va.02.08

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.53

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.57

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.64

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.66

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.48

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.57

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.30

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.94

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.04

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.07.03

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.08

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.07.41

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.76

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.15

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.47

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.65

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.33

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.69

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.61

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.27

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.49

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:pa.03.02

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.101

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.32

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.69

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.18

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.103

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.45

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.21

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.07.31

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.41

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.89

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.71

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.54

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.51

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.10

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.109

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.25

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.41

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.07.45

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.108

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.104

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.31

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.07.50

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.62

Trust: 1.0

vendor:hpmodel:procurve switch 1700-8scope:eqversion: -

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:pa.02.02

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.40

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.102

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:pa.02.08

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:pb.02.08

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.54

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.07.54

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.20

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.24

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.07.55

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.44

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.93

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:pb.03.03

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.83

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.82

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.44

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.28

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.22

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:pb.02.04

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:pb.02.05

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:pb.02.06

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.07.46

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.70

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.80

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.71

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.45

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:pb.02.01

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:pb.03.00

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.46

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:pa.02.03

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.60

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.81

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.105

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.36

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:pb.02.03

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.90

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:pb.02.02

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.75

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.47

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:pa.02.05

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.74

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.46

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.91

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.21

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.20

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.42

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.13

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.92

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.11

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.64

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:pa.02.04

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.23

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.58

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.65

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.48

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.53

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.59

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.16

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.56

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.50

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.07.02

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.61

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.17

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.43

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.56

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.77

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.60

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.52

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.62

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.67

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.95

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:pb.03.04

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.73

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.50

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.12

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.29

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.38

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.85

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.72

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.67

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.30

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:pa.03.04

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.100

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.22

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.07

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.40

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:pb.02.09

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.97

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.74

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.49

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.07.56

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.26

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.78

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.80

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:pa.02.06

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:pa.03.01

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.35

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.86

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.55

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.58

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.98

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.55

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.106

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.37

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.39

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.73

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.107

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:pb.03.02

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.88

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:pb.03.01

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.70

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.84

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.99

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.63

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.72

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:pa.03.03

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.07.53

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:pa.02.09

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.87

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.27

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.07.32

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.19

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.33

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.06

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:pa.02.01

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.14

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.96

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.43

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.79

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.51

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.08.59

Trust: 1.0

vendor:hpmodel:procurve switch 1700-24scope:eqversion: -

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:r.11.28

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:h.10.68

Trust: 1.0

vendor:hpmodel:procurve switch softwarescope:eqversion:pa.02.07

Trust: 1.0

vendor:hewlett packard l pmodel:procurve switch 1700-24scope:lteversion:switch (j9080a) vb.02.08

Trust: 0.8

vendor:hewlett packard l pmodel:procurve switch 1700-8scope:lteversion:switch (j9079a) va.02.08

Trust: 0.8

vendor:hewlett packardmodel:procurve switch 1700-24scope: - version: -

Trust: 0.8

vendor:hewlett packardmodel:procurve switch 1700-8scope: - version: -

Trust: 0.8

vendor:hewlett packardmodel:procurve switch softwarescope:ltversion:va.02.09 (1700-8)

Trust: 0.8

vendor:hewlett packardmodel:procurve switch softwarescope:ltversion:vb.02.09 (1700-24)

Trust: 0.8

vendor:hpmodel:procurve switchscope:eqversion:1700-8

Trust: 0.6

vendor:hpmodel:procurve switchscope:eqversion:1700-24

Trust: 0.6

vendor:procurve switchmodel:hscope: - version: -

Trust: 0.4

vendor:procurve switchmodel:h.07.02scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.07.03scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.07.31scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.07.32scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.07.41scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.07.45scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.07.46scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.07.50scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.07.53scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.07.54scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.07.55scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.07.56scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.53scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.55scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.56scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.57scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.58scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.59scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.60scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.61scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.62scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.64scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.65scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.67scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.69scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.70scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.71scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.72scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.73scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.74scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.75scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.76scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.77scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.78scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.79scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.80scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.81scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.82scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.83scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.84scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.85scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.86scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.87scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.88scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.89scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.90scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.91scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.92scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.93scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.94scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.95scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.96scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.97scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.98scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.99scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.100scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.101scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.102scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.103scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.104scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.105scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.106scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.107scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.108scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.08.109scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.10.20scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.10.21scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.10.22scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.10.23scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.10.24scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.10.25scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.10.26scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.10.27scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.10.28scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.10.29scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.10.30scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.10.31scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.10.32scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.10.33scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.10.35scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.10.36scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.10.37scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.10.38scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.10.39scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.10.40scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.10.41scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.10.42scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.10.43scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.10.44scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.10.45scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.10.46scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.10.47scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.10.48scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.10.49scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.10.50scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.10.51scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.10.52scope: - version: -

Trust: 0.2

vendor:procurve switchmodel:h.10.53scope: - version: -

Trust: 0.2

sources: IVD: 0565d2e6-2353-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-02256 // JVNDB: JVNDB-2013-000052 // JVNDB: JVNDB-2013-002089 // CNNVD: CNNVD-201303-540 // NVD: CVE-2012-5216

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2012-5216
value: MEDIUM

Trust: 1.0

IPA: JVNDB-2013-000052
value: LOW

Trust: 0.8

CNVD: CNVD-2013-02256
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201303-540
value: MEDIUM

Trust: 0.6

IVD: 0565d2e6-2353-11e6-abef-000c29c66e3d
value: MEDIUM

Trust: 0.2

VULHUB: VHN-58497
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2012-5216
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

IPA: JVNDB-2013-000052
severity: LOW
baseScore: 2.6
vectorString: AV:N/AC:H/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: HIGH
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

CNVD: CNVD-2013-02256
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: 0565d2e6-2353-11e6-abef-000c29c66e3d
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

VULHUB: VHN-58497
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: IVD: 0565d2e6-2353-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-02256 // VULHUB: VHN-58497 // JVNDB: JVNDB-2013-000052 // CNNVD: CNNVD-201303-540 // NVD: CVE-2012-5216

PROBLEMTYPE DATA

problemtype:CWE-352

Trust: 1.9

sources: VULHUB: VHN-58497 // JVNDB: JVNDB-2013-000052 // NVD: CVE-2012-5216

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201303-540

TYPE

cross-site request forgery

Trust: 0.6

sources: CNNVD: CNNVD-201303-540

CONFIGURATIONS

sources: JVNDB: JVNDB-2013-000052

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-58497

PATCH

title:HP ProCurve 1700-8(J9079A) and 1700-24(J9080A) Switches, Cross Site Request Forgery (CSRF)url:https://h20566.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03699981

Trust: 0.8

title:HPSBPV02855 SSRT100512url:http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c03699981

Trust: 0.8

title:Patch for HP ProCurve Switches cross-site request forgery vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/33034

Trust: 0.6

sources: CNVD: CNVD-2013-02256 // JVNDB: JVNDB-2013-000052 // JVNDB: JVNDB-2013-002089

EXTERNAL IDS

db:NVDid:CVE-2012-5216

Trust: 4.5

db:JVNid:JVN48108258

Trust: 2.5

db:BIDid:58701

Trust: 1.0

db:CNNVDid:CNNVD-201303-540

Trust: 0.9

db:CNVDid:CNVD-2013-02256

Trust: 0.8

db:JVNDBid:JVNDB-2013-000052

Trust: 0.8

db:JVNDBid:JVNDB-2013-002089

Trust: 0.8

db:IVDid:0565D2E6-2353-11E6-ABEF-000C29C66E3D

Trust: 0.2

db:PACKETSTORMid:120959

Trust: 0.2

db:VULHUBid:VHN-58497

Trust: 0.1

sources: IVD: 0565d2e6-2353-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-02256 // VULHUB: VHN-58497 // BID: 58701 // JVNDB: JVNDB-2013-000052 // JVNDB: JVNDB-2013-002089 // PACKETSTORM: 120959 // CNNVD: CNNVD-201303-540 // NVD: CVE-2012-5216

REFERENCES

url:http://jvn.jp/en/jp/jvn48108258/index.html

Trust: 2.5

url:https://h20566.www2.hp.com/portal/site/hpsc/public/kb/docdisplay?docid=emr_na-c03699981

Trust: 1.7

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2012-5216

Trust: 1.6

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2012-5216

Trust: 1.6

url:http://seclists.org/bugtraq/2013/mar/131

Trust: 0.6

url:https://nvd.nist.gov/vuln/detail/cve-2012-5216

Trust: 0.1

url:http://h20566.www2.hp.com/portal/site/hpsc/public/kb/secbullarchive/

Trust: 0.1

url:http://h41183.www4.hp.com/signup_alerts.php?jumpid=hpsc_secbulletins

Trust: 0.1

url:https://h20566.www2.hp.com/portal/site/hpsc/public/kb/

Trust: 0.1

sources: CNVD: CNVD-2013-02256 // VULHUB: VHN-58497 // JVNDB: JVNDB-2013-000052 // JVNDB: JVNDB-2013-002089 // PACKETSTORM: 120959 // CNNVD: CNNVD-201303-540 // NVD: CVE-2012-5216

CREDITS

The vendor reported this issue.

Trust: 0.3

sources: BID: 58701

SOURCES

db:IVDid:0565d2e6-2353-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2013-02256
db:VULHUBid:VHN-58497
db:BIDid:58701
db:JVNDBid:JVNDB-2013-000052
db:JVNDBid:JVNDB-2013-002089
db:PACKETSTORMid:120959
db:CNNVDid:CNNVD-201303-540
db:NVDid:CVE-2012-5216

LAST UPDATE DATE

2025-04-11T23:20:36.064000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2013-02256date:2013-05-27T00:00:00
db:VULHUBid:VHN-58497date:2019-10-09T00:00:00
db:BIDid:58701date:2013-03-25T00:00:00
db:JVNDBid:JVNDB-2013-000052date:2013-06-03T00:00:00
db:JVNDBid:JVNDB-2013-002089date:2013-04-02T00:00:00
db:CNNVDid:CNNVD-201303-540date:2019-10-17T00:00:00
db:NVDid:CVE-2012-5216date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:IVDid:0565d2e6-2353-11e6-abef-000c29c66e3ddate:2013-04-01T00:00:00
db:CNVDid:CNVD-2013-02256date:2013-03-28T00:00:00
db:VULHUBid:VHN-58497date:2013-03-28T00:00:00
db:BIDid:58701date:2013-03-25T00:00:00
db:JVNDBid:JVNDB-2013-000052date:2013-06-03T00:00:00
db:JVNDBid:JVNDB-2013-002089date:2013-04-02T00:00:00
db:PACKETSTORMid:120959date:2013-03-26T19:01:00
db:CNNVDid:CNNVD-201303-540date:2013-03-27T00:00:00
db:NVDid:CVE-2012-5216date:2013-03-28T23:55:01.400