CVE-2013-2342
high
CVSS v3
—
CVSS v2
7.7
VIR risk
7.7
Description
The HP StoreOnce D2D backup system with software before 3.0.0 has a default password of badg3r5 for the HPSupport account, which allows remote attackers to obtain administrative access and delete data via an SSH session.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: hp-security-alert@hp.com — https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03813919
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| hp | storeonce_d2d | {"endIncluding":"2.2.17"} | |
| hp | storeonce_d2d | 2.1.01 | |
| hp | storeonce_d2d | 2.2.00 | |
| hp | storeonce_d2d | 2.2.10 | |
| hp | storeonce_d2d | 2.2.13 | |
| hp | storeonce_d2d | 2.2.14 | |
| hp | storeonce_d2d | 2.2.16 | |
References
CWEs
CWE-255
Verify integrity in audit chain (admin only). AS-IS.