PT-2001-2036 · Alchemy · Alchemy Network Monitor+1
Publicado
2001-11-30
·
Atualizado
2017-12-19
·
CVE-2001-0870
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Alchemy Eye and Alchemy Network Monitor versions 1.9x through 2.6.18
Description
The HTTP server in the affected software is enabled without authentication by default. This allows remote attackers to obtain network monitoring logs, which may contain sensitive information, by directly requesting the eye.ini file.
Recommendations
For versions 1.9x through 2.6.18, consider disabling the HTTP server or configuring it to require authentication to prevent unauthorized access to network monitoring logs.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alchemy Eye
Alchemy Network Monitor