PT-2002-2670 · Iomega · Iomega Nas A300U

CVE-2002-1949

·

Publicado

2002-12-31

·

Atualizado

2024-01-25

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Iomega NAS A300U
Description The issue concerns the transmission of passwords in cleartext by the Network Attached Storage (NAS) Administration Web Page, allowing remote attackers to intercept the administrative password.
Recommendations For Iomega NAS A300U, consider disabling the web administration interface until a fix is available to prevent remote attackers from sniffing the administrative password. Restrict access to the administrative web page to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Cleartext Transmission of Sensitive Information

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2002-1949

Produtos afetados

Iomega Nas A300U