Web configuration utility in HP AdvanceStack hubs J3200A through J3210A with firmware version A.03.07 and earlier, allows unauthorized users to bypass authentication via a direct HTTP request to the web_access.html file, which allows the user to change the switchs configuration and modify the administrator password.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Advancestack_10base-t_switching_hub_j3200a | Hp | a.03.07 (including) | a.03.07 (including) |
Advancestack_10base-t_switching_hub_j3201a | Hp | a.03.07 (including) | a.03.07 (including) |
Advancestack_10base-t_switching_hub_j3202a | Hp | a.03.07 (including) | a.03.07 (including) |
Advancestack_10base-t_switching_hub_j3203a | Hp | a.03.07 (including) | a.03.07 (including) |
Advancestack_10base-t_switching_hub_j3204a | Hp | a.03.07 (including) | a.03.07 (including) |
Advancestack_10base-t_switching_hub_j3205a | Hp | a.03.07 (including) | a.03.07 (including) |
Advancestack_10base-t_switching_hub_j3210a | Hp | a.03.07 (including) | a.03.07 (including) |