Cleartext Credential Exposure in Huawei D100 Devices
CVE-2009-2272
7.5HIGH
Summary
The Huawei D100 device exposes administrator credentials by storing account names and passwords in plain text within cookies. This vulnerability allows attackers to access sensitive information through various means, including reading cookie files, intercepting HTTP headers, and potentially exploiting additional, unspecified methods. Organizations using the D100 should take immediate steps to mitigate the risks associated with this vulnerability to ensure the protection of critical information.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved