Other HPE Product Questions
1824219 Members
4129 Online
109669 Solutions
New Discussion

Vulnerabilities Lighttpd in the HPE OfficeConnect Switch 1820 24G J9980A

 
paulo_rribeiro
Occasional Visitor

Vulnerabilities Lighttpd in the HPE OfficeConnect Switch 1820 24G J9980A

In our inspection routines we found vulnerabilities in the HPE OfficeConnect Switch 1820 24G J9980A.
vulnerabilities: Lighttpd < 1.4.35 Multiple Vulnerabilities - Active Check

Vulnerability Insight
The following flaws exist:
- mod_mysql_vhost module is not properly sanitizing user supplied input passed via the host-
name
- mod_evhost and mod_simple_vhost modules are not properly sanitizing user supplied input
via the hostname.

Vulnerability Detection Method
Sends a crafted HTTP GET request and checks the response.
Details: Lighttpd < 1.4.35 Multiple Vulnerabilities - Active Check
OID:1.3.6.1.4.1.25623.1.0.802072
Version used: 2023-02-01T10:08:40Z

References
cve: CVE-2014-2323
cve: CVE-2014-2324


I need help on how to resolve this vulnerability

 

Thanks

1 REPLY 1
Sunitha_Mod
Moderator

Re: Vulnerabilities Lighttpd in the HPE OfficeConnect Switch 1820 24G J9980A

Hello @paulo_rribeiro,

Thank you for posting.

HPE Networking forum has moved to Aruba Airheads Community and for HPE networking and Aruba product queries, we request you to visit and post your query here: Aruba Airheads Community 

You can refer to the below link as well for more details:

HPE Networking forum migration to Aruba Airheads c... - Hewlett Packard Enterprise Community



Thanks,
Sunitha G
I'm an HPE employee.
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
Accept or Kudo