ID

VAR-201908-0111


CVE

CVE-2019-5401


TITLE

HP2910al-48G Vulnerable to cross-site scripting

Trust: 0.8

sources: JVNDB: JVNDB-2019-007410

DESCRIPTION

A potential security vulnerability has been identified in HP2910al-48G version W.15.14.0016. The attack exploits an xss injection by setting the attack vector in one of the switch persistent configuration fields (management URL, location, contact). But admin privileges are required to configure these fields thereby reducing the likelihood of exploit. HPE Aruba has provided firmware updates to resolve the vulnerability in HP 2910-48G al Switch. Please update to W.15.14.0017. HP2910al-48G Contains a cross-site scripting vulnerability.Information may be obtained and information may be altered. HP 2910al-48G is an Ethernet switch from Hewlett Packard Enterprise (HPE). An arbitrary command execution vulnerability exists in the HP 2910al-48G W.15.14.0016 version. Attackers can use this vulnerability to execute arbitrary commands

Trust: 2.25

sources: NVD: CVE-2019-5401 // JVNDB: JVNDB-2019-007410 // CNVD: CNVD-2019-44746 // VULHUB: VHN-156836

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2019-44746

AFFECTED PRODUCTS

vendor:hpmodel:hp2910al-48gscope:eqversion:w.15.14.00.16

Trust: 1.0

vendor:hewlett packardmodel:hp2910al-48gscope:eqversion:w.15.14.0016

Trust: 0.8

vendor:hpmodel:2910al-48g w.15.14.0016scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2019-44746 // JVNDB: JVNDB-2019-007410 // NVD: CVE-2019-5401

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-5401
value: MEDIUM

Trust: 1.0

NVD: CVE-2019-5401
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2019-44746
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201908-164
value: MEDIUM

Trust: 0.6

VULHUB: VHN-156836
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2019-5401
severity: LOW
baseScore: 3.5
vectorString: AV:N/AC:M/AU:S/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 6.8
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2019-44746
severity: MEDIUM
baseScore: 4.1
vectorString: AV:L/AC:M/AU:S/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 2.7
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-156836
severity: LOW
baseScore: 3.5
vectorString: AV:N/AC:M/AU:S/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 6.8
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2019-5401
baseSeverity: MEDIUM
baseScore: 4.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 1.7
impactScore: 2.7
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2019-44746 // VULHUB: VHN-156836 // JVNDB: JVNDB-2019-007410 // CNNVD: CNNVD-201908-164 // NVD: CVE-2019-5401

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-156836 // JVNDB: JVNDB-2019-007410 // NVD: CVE-2019-5401

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201908-164

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201908-164

CONFIGURATIONS

sources: JVNDB: JVNDB-2019-007410

PATCH

title:hpesbhf03944en_usurl:https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03944en_us

Trust: 0.8

title:Patch for HP 2910al-48G arbitrary command execution vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/193663

Trust: 0.6

title:HP 2910al-48G Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=95924

Trust: 0.6

sources: CNVD: CNVD-2019-44746 // JVNDB: JVNDB-2019-007410 // CNNVD: CNNVD-201908-164

EXTERNAL IDS

db:NVDid:CVE-2019-5401

Trust: 3.1

db:AUSCERTid:ESB-2019.3035

Trust: 1.2

db:JVNDBid:JVNDB-2019-007410

Trust: 0.8

db:CNNVDid:CNNVD-201908-164

Trust: 0.7

db:CNVDid:CNVD-2019-44746

Trust: 0.6

db:VULHUBid:VHN-156836

Trust: 0.1

sources: CNVD: CNVD-2019-44746 // VULHUB: VHN-156836 // JVNDB: JVNDB-2019-007410 // CNNVD: CNNVD-201908-164 // NVD: CVE-2019-5401

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2019-5401

Trust: 2.0

url:https://www.auscert.org.au/bulletins/esb-2019.3035/

Trust: 1.2

url:https://support.hpe.com/hpsc/doc/public/display?doclocale=en_us&docid=emr_na-hpesbhf03944en_us

Trust: 1.0

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-5401

Trust: 0.8

url:https://support.hpe.com/hpsc/doc/public/display?docid=hpesbhf03944en_us

Trust: 0.6

url:https://support.hpe.com/hpsc/doc/public/display?doclocale=en_us&docid=emr_na-hpesbhf03944en_us

Trust: 0.1

sources: CNVD: CNVD-2019-44746 // VULHUB: VHN-156836 // JVNDB: JVNDB-2019-007410 // CNNVD: CNNVD-201908-164 // NVD: CVE-2019-5401

SOURCES

db:CNVDid:CNVD-2019-44746
db:VULHUBid:VHN-156836
db:JVNDBid:JVNDB-2019-007410
db:CNNVDid:CNNVD-201908-164
db:NVDid:CVE-2019-5401

LAST UPDATE DATE

2024-11-23T22:11:56.483000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2019-44746date:2019-12-11T00:00:00
db:VULHUBid:VHN-156836date:2019-08-08T00:00:00
db:JVNDBid:JVNDB-2019-007410date:2019-08-09T00:00:00
db:CNNVDid:CNNVD-201908-164date:2019-09-04T00:00:00
db:NVDid:CVE-2019-5401date:2024-11-21T04:44:52.380

SOURCES RELEASE DATE

db:CNVDid:CNVD-2019-44746date:2019-12-11T00:00:00
db:VULHUBid:VHN-156836date:2019-08-01T00:00:00
db:JVNDBid:JVNDB-2019-007410date:2019-08-09T00:00:00
db:CNNVDid:CNNVD-201908-164date:2019-08-01T00:00:00
db:NVDid:CVE-2019-5401date:2019-08-01T22:15:12.037