Hewlett Packard Enterprise OfficeConnect 安全漏洞
CVE编号
CVE-2022-37932利用情况
暂无补丁情况
N/A披露时间
2022-12-12漏洞描述
Hewlett Packard Enterprise OfficeConnect是美国慧与(Hewlett Packard Enterprise)公司的一系列交换机。Hewlett Packard Enterprise OfficeConnect 1820、1850 和 1920S Network switches存在安全漏洞,该漏洞源于发现了一个潜在的安全漏洞,该漏洞可被远程利用以绕过身份验证,以下产品和版本受到影响:PT.02.14 之前版本、 在 PC.01.22 之前版本;、在 PO.01.21 之前版本、 在 PD.02.22 之前版本。解决建议
建议您更新当前系统或软件至最新版,完成漏洞的修复。
参考链接 |
|
---|---|
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-... |
受影响软件情况
# | 类型 | 厂商 | 产品 | 版本 | 影响面 | ||||
1 | |||||||||
---|---|---|---|---|---|---|---|---|---|
运行在以下环境 | |||||||||
系统 | hpe | officeconnect_1820_j9979a_firmware | * | Up to (excluding) pt.02.14 | |||||
运行在以下环境 | |||||||||
系统 | hpe | officeconnect_1820_j9980a_firmware | * | Up to (excluding) pt.02.14 | |||||
运行在以下环境 | |||||||||
系统 | hpe | officeconnect_1820_j9981a_firmware | * | Up to (excluding) pt.02.14 | |||||
运行在以下环境 | |||||||||
系统 | hpe | officeconnect_1820_j9982a_firmware | * | Up to (excluding) pt.02.14 | |||||
运行在以下环境 | |||||||||
系统 | hpe | officeconnect_1820_j9983a_firmware | * | Up to (excluding) pt.02.14 | |||||
运行在以下环境 | |||||||||
系统 | hpe | officeconnect_1820_j9984a_firmware | * | Up to (excluding) pt.02.14 | |||||
运行在以下环境 | |||||||||
系统 | hpe | officeconnect_1850_24g_2xgt_firmware | * | Up to (excluding) pc.01.22 | |||||
运行在以下环境 | |||||||||
系统 | hpe | officeconnect_1850_24g_2xgt_poe+_firmware | * | Up to (excluding) pc.01.22 | |||||
运行在以下环境 | |||||||||
系统 | hpe | officeconnect_1850_2xgt/spf+_firmware | * | Up to (excluding) po.01.21 | |||||
运行在以下环境 | |||||||||
系统 | hpe | officeconnect_1850_48g_4xgt_firmware | * | Up to (excluding) pc.01.22 | |||||
运行在以下环境 | |||||||||
系统 | hpe | officeconnect_1850_48g_4xgt_poe+_firmware | * | Up to (excluding) pc.01.22 | |||||
运行在以下环境 | |||||||||
系统 | hpe | officeconnect_1850_6xgt_firmware | * | Up to (excluding) po.01.21 | |||||
运行在以下环境 | |||||||||
系统 | hpe | officeconnect_1920s_24g_2sfp_firmware | * | Up to (excluding) pd.02.22 | |||||
运行在以下环境 | |||||||||
系统 | hpe | officeconnect_1920s_24g_2sfp_poe+_firmware | * | Up to (excluding) pd.02.22 | |||||
运行在以下环境 | |||||||||
系统 | hpe | officeconnect_1920s_24g_2sfp_ppoe+_firmware | * | Up to (excluding) pd.02.22 | |||||
运行在以下环境 | |||||||||
系统 | hpe | officeconnect_1920s_48g_4sfp_firmware | * | Up to (excluding) pd.02.22 | |||||
运行在以下环境 | |||||||||
系统 | hpe | officeconnect_1920s_48g_4sfp_ppoe+_firmware | * | Up to (excluding) pd.02.22 | |||||
运行在以下环境 | |||||||||
系统 | hpe | officeconnect_1920s_8g_firmware | * | Up to (excluding) pd.02.22 | |||||
运行在以下环境 | |||||||||
系统 | hpe | officeconnect_1920s_8g_ppoe+_firmware | * | Up to (excluding) pd.02.22 | |||||
运行在以下环境 | |||||||||
硬件 | hpe | officeconnect_1820_j9979a | - | - | |||||
运行在以下环境 | |||||||||
硬件 | hpe | officeconnect_1820_j9980a | - | - | |||||
运行在以下环境 | |||||||||
硬件 | hpe | officeconnect_1820_j9981a | - | - | |||||
运行在以下环境 | |||||||||
硬件 | hpe | officeconnect_1820_j9982a | - | - | |||||
运行在以下环境 | |||||||||
硬件 | hpe | officeconnect_1820_j9983a | - | - | |||||
运行在以下环境 | |||||||||
硬件 | hpe | officeconnect_1820_j9984a | - | - | |||||
运行在以下环境 | |||||||||
硬件 | hpe | officeconnect_1850_24g_2xgt | - | - | |||||
运行在以下环境 | |||||||||
硬件 | hpe | officeconnect_1850_24g_2xgt_poe+ | - | - | |||||
运行在以下环境 | |||||||||
硬件 | hpe | officeconnect_1850_2xgt/spf+ | - | - | |||||
运行在以下环境 | |||||||||
硬件 | hpe | officeconnect_1850_48g_4xgt | - | - | |||||
运行在以下环境 | |||||||||
硬件 | hpe | officeconnect_1850_48g_4xgt_poe+ | - | - | |||||
运行在以下环境 | |||||||||
硬件 | hpe | officeconnect_1850_6xgt | - | - | |||||
运行在以下环境 | |||||||||
硬件 | hpe | officeconnect_1920s_24g_2sfp | - | - | |||||
运行在以下环境 | |||||||||
硬件 | hpe | officeconnect_1920s_24g_2sfp_poe+ | - | - | |||||
运行在以下环境 | |||||||||
硬件 | hpe | officeconnect_1920s_24g_2sfp_ppoe+ | - | - | |||||
运行在以下环境 | |||||||||
硬件 | hpe | officeconnect_1920s_48g_4sfp | - | - | |||||
运行在以下环境 | |||||||||
硬件 | hpe | officeconnect_1920s_48g_4sfp_ppoe+ | - | - | |||||
运行在以下环境 | |||||||||
硬件 | hpe | officeconnect_1920s_8g | - | - | |||||
运行在以下环境 | |||||||||
硬件 | hpe | officeconnect_1920s_8g_ppoe+ | - | - | |||||
- 攻击路径 网络
- 攻击复杂度 低
- 权限要求 无
- 影响范围 未更改
- 用户交互 无
- 可用性 高
- 保密性 高
- 完整性 高
CWE-ID | 漏洞类型 |
CWE-287 | 认证机制不恰当 |
NVD-CWE-noinfo |
Exp相关链接

版权声明
本站原创文章转载请注明文章出处及链接,谢谢合作!
评论