CVE-2012-2986: HP San/iq

High severity, CVSS 7.7. EPSS: 4.4% chance of exploitation in the next 30 days.

lhn/public/network/ping in HP SAN/iQ 9.5 on the HP Virtual SAN Appliance allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) first, (2) third, or (3) fourth parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-4361.

Affected products

  • HP San/iq: version 9.5 only

Published 2012-08-20. Last modified 2026-06-16.