6.8
CVSSv2

CVE-2013-6852

Published: 22/11/2013 Updated: 22/11/2013
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in html/json.html on HP 2620 switches allows remote malicious users to hijack the authentication of administrators for requests that change an administrative password via the setPassword method.

Vulnerable Product Search on Vulmon Subscribe to Product

hp 2620-24-poe\\+ switch -

Exploits

# Exploit Title: Hewlett-Packard 2620 Switch Series Edit Admin Account - CSRF Vulnerability # Date: 26092013r # Exploit Author: Hubert GrÄ…dek (PL) # Software Link: [download link if available] # Tested on: HP-E2620 24-PoEP // RA15050006,ROMRA1510 HTTP Headers: [IP_ADDR]/html/jsonhtml Host: [IP_ADDR] User-Agent: Mozilla/50 ...