CVE-2012-2963
12.08.2012, 16:55
The administrative interface in the embedded web server on the BreakingPoint Storm appliance before 3.0 does not require authentication for the gwt/BugReport script, which allows remote attackers to obtain sensitive information by downloading a .tgz file.Enginsight
Vendor | Product | Version |
---|---|---|
breakingpointsystems | breakingpoint_storm_appliance_ctm | 𝑥 ≤ 2.0 |
breakingpointsystems | breakingpoint_storm_appliance_ctm | 1.2 |
breakingpointsystems | breakingpoint_storm_appliance_ctm | 1.4 |
breakingpointsystems | breakingpoint_storm_appliance_ctm | 1.5 |
breakingpointsystems | breakingpoint_storm_appliance | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration