The BreakingPoint Storm appliance before 3.0 requires cleartext credentials for establishing a session from a GUI administrative client, which allows remote attackers to obtain sensitive information by sniffing the network for XML documents.
References
Link | Resource |
---|---|
http://www.kb.cert.org/vuls/id/520430 | US Government Resource |
http://www.kb.cert.org/vuls/id/MAPG-8GANCC | US Government Resource |
http://www.secureworks.com/research/advisories/SWRX-2012-006/ |
Configurations
Configuration 1 (hide)
AND |
|
History
No history.
Information
Published : 2012-08-12 16:55
Updated : 2024-02-04 18:16
NVD link : CVE-2012-2964
Mitre link : CVE-2012-2964
CVE.ORG link : CVE-2012-2964
JSON object : View
Products Affected
breakingpointsystems
- breakingpoint_storm_appliance_ctm
- breakingpoint_storm_appliance
CWE
CWE-20
Improper Input Validation