CVE-2012-4361 describes a critical command injection vulnerability in the lhn/public/network/ping component of HP SAN/iQ before version 9.5 on the HP Virtual SAN Appliance. This flaw allows remote authenticated attackers to execute arbitrary commands by injecting shell metacharacters into the second parameter. With a CVSS score of 7.7 (AV:A/AC:L/Au:S/C:C/I:C/A:C), the vulnerability is highly severe, requiring network access and authentication, but offering complete compromise of confidentiality, integrity, and availability. Exploit code is publicly available, including a Metasploit module and ExploitDB entries, though it is not listed on CISA's KEV catalog and has minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.0CPE matchmatch criteria | cpe:2.3:a:hp:san\/iq:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:a:hp:san\/iq:8.0:*:*:*:*:*:*:* | ||
8.1CPE matchmatch criteria | cpe:2.3:a:hp:san\/iq:8.1:*:*:*:*:*:*:* | ||
8.5CPE matchmatch criteria | cpe:2.3:a:hp:san\/iq:8.5:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:A/AC:L/Au:S/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP StorageWorks P4000 Virtual SAN Appliance Software Management Service Authentication Bypass Remote Command Execution
Nov 11, 2011HP StorageWorks P4000 Virtual SAN Appliance Software Management Service Authentication Bypass Remote Command Execution
Nov 11, 2011HP StorageWorks P4000 Virtual SAN Appliance Software Management Service Authentication Bypass Remote Command Execution
Nov 11, 2011