EntryPass N5200 Active Network Control Panel does not properly restrict access, which allows remote attackers to obtain the administrator username and password, and possibly other sensitive information, via a request to /4.
References
Configurations
History
21 Nov 2024, 02:19
Type | Values Removed | Values Added |
---|---|---|
References | () http://seclists.org/fulldisclosure/2014/Dec/2 - Exploit | |
References | () http://www.securityfocus.com/archive/1/534128/100/0/threaded - | |
References | () https://www.redteam-pentesting.de/advisories/rt-sa-2014-011 - Exploit |
Information
Published : 2014-12-07 21:59
Updated : 2024-11-21 02:19
NVD link : CVE-2014-8868
Mitre link : CVE-2014-8868
CVE.ORG link : CVE-2014-8868
JSON object : View
Products Affected
entrypass
- n5200_active_network_control_panel
CWE
CWE-264
Permissions, Privileges, and Access Controls