[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256610

 
 

909

 
 

199263

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2004-0190Date: (C)2004-03-15   (M)2023-12-22


Symantec FireWall/VPN Appliance model 200 records a cleartext password for the password administration page, which may be cached on the administrator's local system or in a proxy, which allows attackers to steal the password and gain privileges.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.5
Exploit Score: 10.0
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
http://marc.info/?l=bugtraq&m=107694794031839&w=2
OSVDB-4117
BID-9784
symantec-firewallvpn-password-plaintext(15212)

CPE    3
cpe:/h:symantec:firewall_vpn_appliance_200
cpe:/h:symantec:firewall_vpn_appliance_100
cpe:/h:symantec:firewall_vpn_appliance_200r

© SecPod Technologies