Remote Administration Vulnerability in HP Procurve 4000M Switch
CVE-2002-1147
Currently unrated
Summary
The HTTP administration interface for the HP Procurve 4000M Switch firmware prior to version C.09.16 contains a significant vulnerability. This flaw allows remote attackers to send unauthenticated requests specifically to reset the device, potentially leading to a denial of service. If remote administration is enabled along with the device stacking features, it exacerbates the risk, as attackers can exploit this weakness through direct requests to the device_reset CGI program, effectively disrupting network operations.
References
EPSS Score
5% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved