The web management interface on the LG-Nortel ELO GS24M switch allows remote attackers to bypass authentication, and consequently obtain cleartext credential and configuration information, via a direct request to a configuration web page.
References
Link | Resource |
---|---|
http://www.kb.cert.org/vuls/id/523027 | US Government Resource |
https://exchange.xforce.ibmcloud.com/vulnerabilities/74237 | |
http://osvdb.org/80370 |
Configurations
Information
Published : 2012-03-22 03:17
Updated : 2018-01-09 18:29
NVD link : CVE-2012-1838
Mitre link : CVE-2012-1838
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
lg-nortel
- elo_gs24m_switch