The BreakingPoint Storm appliance before 3.0 requires cleartext credentials for establishing a session from a GUI administrative client, which allows remote attackers to obtain sensitive information by sniffing the network for XML documents.
References
Link | Resource |
---|---|
http://www.kb.cert.org/vuls/id/520430 | US Government Resource |
http://www.kb.cert.org/vuls/id/MAPG-8GANCC | US Government Resource |
http://www.secureworks.com/research/advisories/SWRX-2012-006/ | |
http://www.kb.cert.org/vuls/id/520430 | US Government Resource |
http://www.kb.cert.org/vuls/id/MAPG-8GANCC | US Government Resource |
http://www.secureworks.com/research/advisories/SWRX-2012-006/ |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 01:40
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.kb.cert.org/vuls/id/520430 - US Government Resource | |
References | () http://www.kb.cert.org/vuls/id/MAPG-8GANCC - US Government Resource | |
References | () http://www.secureworks.com/research/advisories/SWRX-2012-006/ - |
Information
Published : 2012-08-12 16:55
Updated : 2024-11-21 01:40
NVD link : CVE-2012-2964
Mitre link : CVE-2012-2964
CVE.ORG link : CVE-2012-2964
JSON object : View
Products Affected
breakingpointsystems
- breakingpoint_storm_appliance
- breakingpoint_storm_appliance_ctm
CWE
CWE-20
Improper Input Validation