CVE-2014-5400
EUVD-2014-528803.04.2015, 10:59
The installation component in Hospira MedNet before 6.1 places cleartext credentials in configuration files, which allows local users to obtain sensitive information by reading a file.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| hospira | mednet | 𝑥 ≤ 5.8 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-260 - Password in Configuration FileThe software stores a password in a configuration file that might be accessible to actors who do not know the password.
- CWE-200 - Exposure of Sensitive Information to an Unauthorized ActorThe product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.