SB2023041253 - Man-in-the-middle attack in HPE Systems Insight Manager
Published: April 12, 2023
Security Bulletin ID
SB2023041253
Severity
High
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Adjecent network
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Man-in-the-middle attack (CVE-ID: CVE-2016-2118)
The vulnerability allows a remote attacker to gain elevated privileges on the system.The vulnerability exists due to the acceptance of inadequate authentication levels by the Microsoft Security Account Manager (SAM) and Local Security Authority (Domain Policy) (LSAD) remote protocols. A remote attacker can gain elevated privileges on the system by using man-in-the-middle techniques to impersonate an authenticated user against the SAMR or LSAD service and gain access to the Security Account Manager (SAM) database.
Successful exploitation of this vulnerability may result in disclosere of sytem information.
Remediation
Install update from vendor's website.