HP acknowledges the presence of a 'backdoor' in its storage products

Advertisement
By Anupam Saxena | Updated: 13 July 2013 14:51 IST
HP (Hewlett Packard) has admitted that its StoreVirtual storage area network (SAN) products contain a 'backdoor' that allows remote access via an administrative account.

This essentially means that anyone with an account username and password meant for backdoor access will be able to log into the systems and gain access to the operating system, which is a big security hole. These backdoors are actually meant for providing remote support to customers and replaced a hard-rest button which used to be present on the hardware to factory reset the systems. HP started including a different backdoor access account into LeftHand 9.0 the custom operating system used by HP's network storage appliance.

HP has promised to deliver a fix by July 19, The Register notes.

The vulnerability was discovered by Technion, a blogger who first brought it to public notice and to HP's notice through its forums and pointed out that these accounts have existed since 2009.

In a new communication bulletin, HP has admitted that its SAN devices have a vulnerability that could be remotely exploited to gain unauthorised access to the device. However, it has said that the backdoor entry does not offer access to the user data stored on the system.

Here's the full text of the communication:

A potential security vulnerability has been identified with the HP StoreVirtual Storage. This vulnerability could be remotely exploited to gain unauthorized access to the device.

All HP StoreVirtual Storage systems are equipped with a mechanism that allows HP support to access the underlying operating system if permission and access is provided by the customer. This functionality cannot be disabled today.

HP has acknowledged this vulnerability and will provide a patch that will allow customers to disable the support access mechanism on or before July 17, 2013.

HP StoreVirtual products are storage appliances that use a custom operating system, LeftHand OS, which is not accessible to the end user. Limited access is available to the user via the HP StoreVirtual Command-Line Interface (CLiQ) however root access is blocked.

Root access may be requested by HP Support in some cases to help customers resolve complex support issues. To facilitate these cases, a challenge-response-based one-time password utility is employed by HP Support to gain root access to systems when the customer has granted permission and network access to the system. The one-time password utility protects the root access to prevent repeated access to the system with the same pass phrase. Root access to the LeftHand OS does not provide access to the user data being stored on the system.

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. OTT Releases of the Week (Feb 16 - Feb 22): Know What to Watch This Weekend
  2. Xiaomi Teases a New Computing Device, New Tablet Expected to Launch Soon
  3. Here's When Xiaomi Will Launch the Xiaomi 17 and Xiaomi 17 Ultra Globally
  4. Motorola Edge 70 Fusion India Launch Teased; Might Launch With This Chip
  5. Realme P4 Lite With 6,300mAh Battery Launched at This Price in India
  6. Poco X8 Pro, X8 Pro Max Colour Options, Design Leaked Online
  7. Hello Bachhon Set for OTT Release on Netflix: See Details
  8. Xiaomi 17T, Xiaomi 17T Tipped to Launch Four Months Earlier Than Usual
  9. Vivo V70 Elite Review: Vivo's V-Series Goes 'Elite'
  1. Redmi A7 Could Launch Soon as Handset Bags Thailand’s NBTC Certification
  2. Poco X8 Pro, Poco X8 Pro Max Design and Colour Options Seen in Leaked Renders
  3. Hello Bachhon OTT Release Date: When and Where to Watch Vineet Kumar Singh Starrer Online?
  4. Xiaomi Teases India Launch of New Computing Device; New Tablet With Keyboard or Laptop Expected
  5. Realme C83 5G India Price, RAM and Storage Configurations Leaked Online
  6. Xiaomi 17 Series Global Launch Date Announced; Xiaomi 17, Xiaomi 17 Ultra Expected to Debut
  7. Google Blocked 266 Million Risky App Installs, Prevented 1.75 Million Policy-Violating Apps in 2025
  8. Motorola Edge 70 Fusion India Launch Teased on Flipkart; Leaked Marketing Image Hints at Snapdragon 7s Gen 4 SoC
  9. Google Releases Gemini 3.1 Pro With Ability to Execute Complex Tasks; Pomelli Gets New Photoshoot Feature
  10. Theatre: The Myth of Reality OTT Release: Where to Watch Kerala Film Critics Award-Winning Movie Online?
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.