ID

VAR-201808-0945


CVE

CVE-2018-7100


TITLE

HPE OfficeConnect 1810 Switch Information disclosure vulnerability in the series

Trust: 0.8

sources: JVNDB: JVNDB-2018-009202

DESCRIPTION

A potential security vulnerability has been identified in HPE OfficeConnect 1810 Switch Series (HP 1810-24G - P.2.22 and previous versions, HP 1810-48G PK.1.34 and previous versions, HP 1810-8 v2 P.2.22 and previous versions). The vulnerability could allow local disclosure of sensitive information. HPE OfficeConnect 1810 Switch The series contains an information disclosure vulnerability.Information may be obtained. HPE1810-24GSwitch, 1810-48GSwitch and 1810-8v2Switch are all switch products of Hewlett Packard Enterprise (HPE). An attacker can exploit this issue to gain access to sensitive information that may aid in further attacks

Trust: 2.52

sources: NVD: CVE-2018-7100 // JVNDB: JVNDB-2018-009202 // CNVD: CNVD-2018-19584 // BID: 105191 // VULHUB: VHN-137132

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2018-19584

AFFECTED PRODUCTS

vendor:hpmodel:officeconnect 1810-8 v2 switchscope:lteversion:p.2.22

Trust: 1.0

vendor:hpmodel:officeconnect 1810-24g switchscope:lteversion:p.2.22

Trust: 1.0

vendor:hpmodel:officeconnect 1810-48g switchscope:lteversion:pk.1.34

Trust: 1.0

vendor:hewlett packardmodel:hpe officeconnect 1810-24g switchscope:lteversion:p.2.22

Trust: 0.8

vendor:hewlett packardmodel:hpe officeconnect 1810-48g switchscope:lteversion:pk.1.34

Trust: 0.8

vendor:hewlett packardmodel:hpe officeconnect 1810-8 v2 switchscope:lteversion:p.2.22

Trust: 0.8

vendor:hpemodel:1810-24g switch <=p.2.22scope: - version: -

Trust: 0.6

vendor:hpemodel:1810-48g switch <=pk.1.34scope: - version: -

Trust: 0.6

vendor:hpemodel:switch <=p.2.22scope:eqversion:1810-8v2

Trust: 0.6

vendor:hpmodel:officeconnect 1810-8 v2 switchscope:eqversion:p.2.22

Trust: 0.6

vendor:hpmodel:officeconnect 1810-24g switchscope:eqversion:p.2.22

Trust: 0.6

vendor:hpmodel:officeconnect 1810-48g switchscope:eqversion:pk.1.34

Trust: 0.6

vendor:hpmodel:officeconnect p.2.22scope:eqversion:1810-8v2

Trust: 0.3

vendor:hpmodel:officeconnect 1810-48g pk.1.34scope: - version: -

Trust: 0.3

vendor:hpmodel:officeconnect 1810-24g p.2.22scope: - version: -

Trust: 0.3

vendor:hpmodel:officeconnect p.2.23scope:neversion:1810-8v2

Trust: 0.3

vendor:hpmodel:officeconnect 1810-48g pk.1.35scope:neversion: -

Trust: 0.3

vendor:hpmodel:officeconnect 1810-24g p.2.23scope:neversion: -

Trust: 0.3

sources: CNVD: CNVD-2018-19584 // BID: 105191 // JVNDB: JVNDB-2018-009202 // CNNVD: CNNVD-201808-436 // NVD: CVE-2018-7100

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-7100
value: MEDIUM

Trust: 1.0

NVD: CVE-2018-7100
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2018-19584
value: LOW

Trust: 0.6

CNNVD: CNNVD-201808-436
value: MEDIUM

Trust: 0.6

VULHUB: VHN-137132
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2018-7100
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2018-19584
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-137132
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-7100
baseSeverity: MEDIUM
baseScore: 5.5
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 1.8
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2018-19584 // VULHUB: VHN-137132 // JVNDB: JVNDB-2018-009202 // CNNVD: CNNVD-201808-436 // NVD: CVE-2018-7100

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:CWE-200

Trust: 0.9

sources: VULHUB: VHN-137132 // JVNDB: JVNDB-2018-009202 // NVD: CVE-2018-7100

THREAT TYPE

local

Trust: 0.9

sources: BID: 105191 // CNNVD: CNNVD-201808-436

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-201808-436

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-009202

PATCH

title:hpesbhf03858en_usurl:https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03858en_us

Trust: 0.8

title:Patch for HPE1810-24GSwitch, 1810-48GSwitch, and 1810-8v2Switch Information Disclosure Vulnerabilitiesurl:https://www.cnvd.org.cn/patchInfo/show/140723

Trust: 0.6

title:HPE 1810-24G Switch , 1810-48G Switch and 1810-8 v2 Switch Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=83892

Trust: 0.6

sources: CNVD: CNVD-2018-19584 // JVNDB: JVNDB-2018-009202 // CNNVD: CNNVD-201808-436

EXTERNAL IDS

db:NVDid:CVE-2018-7100

Trust: 3.4

db:SECTRACKid:1041445

Trust: 1.7

db:JVNDBid:JVNDB-2018-009202

Trust: 0.8

db:CNNVDid:CNNVD-201808-436

Trust: 0.7

db:CNVDid:CNVD-2018-19584

Trust: 0.6

db:BIDid:105191

Trust: 0.4

db:VULHUBid:VHN-137132

Trust: 0.1

sources: CNVD: CNVD-2018-19584 // VULHUB: VHN-137132 // BID: 105191 // JVNDB: JVNDB-2018-009202 // CNNVD: CNNVD-201808-436 // NVD: CVE-2018-7100

REFERENCES

url:https://support.hpe.com/hpsc/doc/public/display?doclocale=en_us&docid=emr_na-hpesbhf03858en_us

Trust: 2.5

url:http://www.securitytracker.com/id/1041445

Trust: 1.7

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-7100

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-7100

Trust: 0.8

url:http://www.hp.com/

Trust: 0.3

url:https://support.hpe.com/hpsc/doc/public/display?doclocale=en_us&amp;docid=emr_na-hpesbhf03858en_us

Trust: 0.1

sources: CNVD: CNVD-2018-19584 // VULHUB: VHN-137132 // BID: 105191 // JVNDB: JVNDB-2018-009202 // CNNVD: CNNVD-201808-436 // NVD: CVE-2018-7100

CREDITS

Kevin Wang

Trust: 0.3

sources: BID: 105191

SOURCES

db:CNVDid:CNVD-2018-19584
db:VULHUBid:VHN-137132
db:BIDid:105191
db:JVNDBid:JVNDB-2018-009202
db:CNNVDid:CNNVD-201808-436
db:NVDid:CVE-2018-7100

LAST UPDATE DATE

2024-11-23T23:08:36.135000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-19584date:2018-09-21T00:00:00
db:VULHUBid:VHN-137132date:2020-08-24T00:00:00
db:BIDid:105191date:2018-08-10T00:00:00
db:JVNDBid:JVNDB-2018-009202date:2018-11-12T00:00:00
db:CNNVDid:CNNVD-201808-436date:2020-10-22T00:00:00
db:NVDid:CVE-2018-7100date:2024-11-21T04:11:38.657

SOURCES RELEASE DATE

db:CNVDid:CNVD-2018-19584date:2018-09-20T00:00:00
db:VULHUBid:VHN-137132date:2018-08-14T00:00:00
db:BIDid:105191date:2018-08-10T00:00:00
db:JVNDBid:JVNDB-2018-009202date:2018-11-12T00:00:00
db:CNNVDid:CNNVD-201808-436date:2018-08-14T00:00:00
db:NVDid:CVE-2018-7100date:2018-08-14T14:29:01.463