For the second time in a month, HP has announced a patch for an easily-exploitable backdoor in one of its storage products.
The latest fix coming out of the troubled Silicon Valley firm is for its StoreVirtual appliances designed to support customers’ virtualised infrastructure. HP admitted the backdoor “could be remotely exploited to gain unauthorized access to the device”.
“HP has acknowledged this vulnerability and will provide a patch that will allow customers to disable the support access mechanism on or before 17 July 2013.”
The firm said root access to the StoreVirtual operating system, LeftHand OS, was not granted to the user but HP support could get that level of access. The problem is that the “one-time” passwords used by HP support to gain root access can be easily guessed.
Fortunately for users, root access to the LeftHand OS “does not provide access to the user data being stored on the system”, although the urgency of HP’s fix suggests hackers with access could still cause plenty of trouble.
Towards the end of last month, HP pushed out a fix for its StoreOnce storage area networking (SAN) product.
The backdoor in that appliance allowed anyone to open up an SSH client, enter the IP address of a StoreOnce device and use the username HPSupport. All that was then needed was to guess the password, thought to have been very simple, to gain access to an admin account.
Details of the vulnerability were made public by Technion in June, before HP issued a patch. Those running software version 3.0.0 or newer were not affected.
What do you know about Internet security? Find out with our quiz!
Welcome to Silicon UK: AI for Your Business Podcast. Today, we explore how AI can…
Japanese tech investment firm SoftBank promises to invest $100bn during Trump's second term to create…
Synopsys to work with start-up SiMa.ai on joint offering to help accelerate development of AI…
Start-up Basis raises $34m in Series A funding round for AI-powered accountancy agent to make…
Data analytics and AI start-up Databricks completes huge $10bn round from major venture capitalists as…
Congo files legal complaints against Apple in France, Belgium alleging company 'complicit' in laundering conflict…