Cisco Mediator Framework 1.5.1 before 1.5.1.build.14-eng, 2.2 before 2.2.1.dev.1, and 3.0 before 3.0.9.release.1 on the Cisco Network Building Mediator NBM-2400 and NBM-4800 and the Richards-Zeta Mediator 2500 does not encrypt XML RPC sessions from operator workstations, which allows remote attackers to discover Administrator credentials by sniffing the network, aka Bug ID CSCtb83505.
References
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 01:12
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/39904 - | |
References | () http://securitytracker.com/id?1024027 - | |
References | () http://www.cisco.com/en/US/products/products_security_advisory09186a0080b2c518.shtml - Patch, Vendor Advisory | |
References | () http://www.kb.cert.org/vuls/id/757804 - US Government Resource | |
References | () http://www.us-cert.gov/control_systems/pdf/ICSA-10-147-01_Cisco_Network_Building_Mediator.pdf - |
Information
Published : 2010-05-27 19:30
Updated : 2024-11-21 01:12
NVD link : CVE-2010-0599
Mitre link : CVE-2010-0599
CVE.ORG link : CVE-2010-0599
JSON object : View
Products Affected
cisco
- mediator_framework
- network_building_mediator_nbm-2400
- network_building_mediator_nbm-4800
- richards-zeta_mediator_2500
CWE
CWE-255
Credentials Management Errors