The BreakingPoint Storm appliance before 3.0 requires cleartext credentials for establishing a session from a GUI administrative client, which allows remote attackers to obtain sensitive information by sniffing the network for XML documents.
References
Link | Resource |
---|---|
http://www.kb.cert.org/vuls/id/MAPG-8GANCC | US Government Resource |
http://www.secureworks.com/research/advisories/SWRX-2012-006/ | |
http://www.kb.cert.org/vuls/id/520430 | US Government Resource |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2012-08-12 09:55
Updated : 2012-08-12 21:00
NVD link : CVE-2012-2964
Mitre link : CVE-2012-2964
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
breakingpointsystems
- breakingpoint_storm_appliance
- breakingpoint_storm_appliance_ctm