HP Lefthand Virtual SAN Appliance Server Diag Request getListSafeTest Buffer Overflow

Strike ID:
E13-47i01
CVSS:
10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C)
False Positive:
f
Variants:
2
Year:
2013

Description

This strike exploits a stack buffer overflow in HP Lefthand's Appliance Server. In this strike the default credentials are used to issue a Diag request to the hydra service. Because of improper validation if the diag value in getListSafeTest and getListSupportTest requests. A maximum heap buffer of 0x1000 bytes is allocated in which the value is strcpy to. If a null character is found at the end of this data when copied into the buffer the internal source pointer advances to the next byte or the first byte of the destination buffer. The internal destination pointer of strcpy will then move past 0x2000 bytes causing a heap buffer overflow.

CVE