CVE-2012-2964
Published Aug 12, 2012
Last updated 12 years ago
Overview
- Description
- The BreakingPoint Storm appliance before 3.0 requires cleartext credentials for establishing a session from a GUI administrative client, which allows remote attackers to obtain sensitive information by sniffing the network for XML documents.
- Source
- cret@cert.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-20
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:breakingpointsystems:breakingpoint_storm_appliance_ctm:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0078011B-0E74-4B28-86B2-1846376EB92F", "versionEndIncluding": "2.0" }, { "criteria": "cpe:2.3:o:breakingpointsystems:breakingpoint_storm_appliance_ctm:1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1F67D0F6-DCDB-44A7-8D22-76F98651E4AF" }, { "criteria": "cpe:2.3:o:breakingpointsystems:breakingpoint_storm_appliance_ctm:1.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "289B6569-1C90-424E-A9AB-487FAED24337" }, { "criteria": "cpe:2.3:o:breakingpointsystems:breakingpoint_storm_appliance_ctm:1.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3AF5F962-C041-40E0-A63D-8805159062E8" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:breakingpointsystems:breakingpoint_storm_appliance:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E926FFE9-0B2F-4A4E-A3F1-ED8DE9CF74E6" } ], "operator": "OR" } ], "operator": "AND" } ]