Inconsistent interpretation of HTTP requests in HPE products - CVE-2023-30910
Published: April 17, 2025
Vulnerability details
The vulnerability allows a remote user to perform HTTP request smuggling attacks.
The vulnerability exists due to improper validation of HTTP requests. A remote user can send a specially crafted HTTP request to the server and smuggle arbitrary HTTP headers.
Successful exploitation of vulnerability may allow an attacker to poison HTTP cache and perform phishing attacks.
Affected software
HPE MSA 2060 Storage
HPE MSA 1060 Storage
How to mitigate CVE-2023-30910
HPE MSA 2060 Storage - update to IN210R004
HPE MSA 1060 Storage - update to IN210R004