LeftHand Virtual SAN
The flaw exists within the hydra service, specifically with the hel.module component. This process listens on TCP port 13838. When attempting to service a disk diag request the process fails to properly verify the length of the accompanying request paramemeters before copying to a local buffer. A remote attacker can exploit this vulnerability to execute arbitrary code under the context of the root user.
Hewlett-Packard has issued an update to correct this vulnerability. More details can be found at: