CVE-2002-1147
Summary
| CVE | CVE-2002-1147 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2002-10-11 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The HTTP administration interface for HP Procurve 4000M Switch firmware before C.09.16, with stacking features and remote administration enabled, does not authenticate requests to reset the device, which allows remote attackers to cause a denial of service via a direct request to the device_reset CGI program. |
Risk And Classification
Primary CVSS: v2.0 7.1 from [email protected]
AV:N/AC:M/Au:N/C:N/I:N/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
CompleteAV:N/AC:M/Au:N/C:N/I:N/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Hp | Procurve Switch 4000m | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 'HP Procurve 4000M Stacked Switch HTTP Reset Vulnerability' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| HP Procurve 4000M Switch Device Reset Denial Of Service Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| ISS X-Force Database: hp-procurve-http-reset-dos (10172): HP Procurve HTTP reset request denial of service | af854a3a-2127-422b-91ae-364da2661108 | www.iss.net | Vendor Advisory |
| SecurityFocus HOME Advisories: Security Vulnerability in ProCurve switches | af854a3a-2127-422b-91ae-364da2661108 | online.securityfocus.com | Vendor Advisory |
| Techserve, Inc. | af854a3a-2127-422b-91ae-364da2661108 | www.tech-serve.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.