The web interface for American Power Conversion (APC) PowerChute Network Shutdown performs all communication in cleartext (base64-encoded), which allows remote attackers to sniff authentication credentials.
References
Configurations
History
21 Nov 2024, 00:03
Type | Values Removed | Values Added |
---|---|---|
References | () http://nam-en.apc.com/cgi-bin/nam_en.cfg/php/enduser/std_adp.php?p_faqid=7330 - Vendor Advisory | |
References | () http://securitytracker.com/alerts/2005/Nov/1015250.html - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/23183 - |
Information
Published : 2005-12-17 11:03
Updated : 2024-11-21 00:03
NVD link : CVE-2005-4326
Mitre link : CVE-2005-4326
CVE.ORG link : CVE-2005-4326
JSON object : View
Products Affected
apc
- powerchute_network_shutdown
CWE