Vulnerability Name:

CVE-2011-1855 (CCN-67406)

Assigned:2011-05-10
Published:2011-05-10
Updated:2011-09-22
Summary:Unspecified vulnerability in HP Network Node Manager i (NNMi) 9.0x allows local users to read or modify (1) log files or (2) other data via unknown vectors.
CVSS v3 Severity:3.9 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:L/AC:L/Au:S/C:P/I:P/A:P)
3.2 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:S/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
3.2 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:P/I:P/A:N)
2.4 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:S/C:P/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-noinfo
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2011-1855

Source: HP
Type: Vendor Advisory
SSRT100485

Source: CCN
Type: SA44575
HP Network Node Manager i Data and Log Files Access Security Issue

Source: SREASON
Type: UNKNOWN
8249

Source: CCN
Type: OSVDB ID: 73162
HP Network Node Manager i (NNMi) Unspecified Local Log File Access

Source: CCN
Type: BID-47803
HP Network Node Manager i Local Security Bypass Vulnerability

Source: SECTRACK
Type: UNKNOWN
1025520

Source: XF
Type: UNKNOWN
hp-nnmi-security-bypass(67406)

Source: CCN
Type: HP Security Bulletin HPSBMA02672 SSRT100485 rev.
HP Network Node Manager i (NNMi) for HP-UX, Linux, Solaris, and Windows, Local Read and Write Access to Data and Log Files

Vulnerable Configuration:Configuration 1:
  • cpe:/a:hp:network_node_manager_i:9.0:*:*:*:*:*:*:*
  • OR cpe:/a:hp:network_node_manager_i:9.00:*:*:*:*:*:*:*
  • OR cpe:/a:hp:network_node_manager_i:9.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:hp:network_node_manager_i:9.01:*:*:*:*:*:*:*
  • OR cpe:/a:hp:network_node_manager_i:9.02:*:*:*:*:*:*:*
  • OR cpe:/a:hp:network_node_manager_i:9.03:*:*:*:*:*:*:*
  • OR cpe:/a:hp:network_node_manager_i:9.10:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:hp:network_node_manager_i:9.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    hp network node manager i 9.0
    hp network node manager i 9.00
    hp network node manager i 9.0.0
    hp network node manager i 9.01
    hp network node manager i 9.02
    hp network node manager i 9.03
    hp network node manager i 9.10
    hp network node manager i 9.0