CVE-2013-2352

critical HPE
CVSS v3 Base Score
9.4
AV:N/AC:L/Au:N/C:N/I:C/A:C
EPSS Score
2.3%
Exploitation probability in 30 days
Top 15% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Confidentiality
None
Integrity
C
Availability
C
Published: July 10, 2013 (4691 days ago)
Last Modified: April 29, 2026
Vendor: HPE
Source: NVD

Description

LeftHand OS (aka SAN iQ) 10.5 and earlier on HP StoreVirtual Storage devices does not provide a mechanism for disabling the HP Support challenge-response root-login feature, which makes it easier for remote attackers to obtain administrative access by leveraging knowledge of an unused one-time password.

CWE

CWE-255

Affected Products

hp san\/iq

References