CVE-2017-5810
Hewlett Packard Enterprise Network Automation RedirectServlet SQL Injection Remote Code Execution Vulnerability
Severity Score
9.8
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
A remote sql injection vulnerability in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found.
Se ha encontrado una vulnerabilidad de inyección SQL remota en HPE Network Automation 9.1x, 9.2x, 10.0x, 10.1x y 10.2x.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Hewlett Packard Enterprise Network Automation. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the RedirectServlet component. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute SQL under the context of SYSTEM.
*Credits:
rgod
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2017-02-01 CVE Reserved
- 2017-05-05 CVE Published
- 2024-09-17 CVE Updated
- 2024-10-28 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/98331 | Third Party Advisory | |
http://www.securitytracker.com/id/1038407 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbgn03740en_us | 2018-03-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Hp Search vendor "Hp" | Network Automation Search vendor "Hp" for product "Network Automation" | 9.10 Search vendor "Hp" for product "Network Automation" and version "9.10" | - |
Affected
| ||||||
Hp Search vendor "Hp" | Network Automation Search vendor "Hp" for product "Network Automation" | 9.20 Search vendor "Hp" for product "Network Automation" and version "9.20" | - |
Affected
| ||||||
Hp Search vendor "Hp" | Network Automation Search vendor "Hp" for product "Network Automation" | 9.22 Search vendor "Hp" for product "Network Automation" and version "9.22" | - |
Affected
| ||||||
Hp Search vendor "Hp" | Network Automation Search vendor "Hp" for product "Network Automation" | 9.22.01 Search vendor "Hp" for product "Network Automation" and version "9.22.01" | - |
Affected
| ||||||
Hp Search vendor "Hp" | Network Automation Search vendor "Hp" for product "Network Automation" | 9.22.02 Search vendor "Hp" for product "Network Automation" and version "9.22.02" | - |
Affected
| ||||||
Hp Search vendor "Hp" | Network Automation Search vendor "Hp" for product "Network Automation" | 10.00 Search vendor "Hp" for product "Network Automation" and version "10.00" | - |
Affected
| ||||||
Hp Search vendor "Hp" | Network Automation Search vendor "Hp" for product "Network Automation" | 10.00.01 Search vendor "Hp" for product "Network Automation" and version "10.00.01" | - |
Affected
| ||||||
Hp Search vendor "Hp" | Network Automation Search vendor "Hp" for product "Network Automation" | 10.00.02 Search vendor "Hp" for product "Network Automation" and version "10.00.02" | - |
Affected
| ||||||
Hp Search vendor "Hp" | Network Automation Search vendor "Hp" for product "Network Automation" | 10.10 Search vendor "Hp" for product "Network Automation" and version "10.10" | - |
Affected
| ||||||
Hp Search vendor "Hp" | Network Automation Search vendor "Hp" for product "Network Automation" | 10.11 Search vendor "Hp" for product "Network Automation" and version "10.11" | - |
Affected
| ||||||
Hp Search vendor "Hp" | Network Automation Search vendor "Hp" for product "Network Automation" | 10.21 Search vendor "Hp" for product "Network Automation" and version "10.21" | - |
Affected
|