PT-2001-2036 · Alchemy · Alchemy Network Monitor+1

Publicado

2001-11-30

·

Atualizado

2017-12-19

·

CVE-2001-0870

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Alchemy Eye and Alchemy Network Monitor versions 1.9x through 2.6.18
Description The HTTP server in the affected software is enabled without authentication by default. This allows remote attackers to obtain network monitoring logs, which may contain sensitive information, by directly requesting the eye.ini file.
Recommendations For versions 1.9x through 2.6.18, consider disabling the HTTP server or configuring it to require authentication to prevent unauthorized access to network monitoring logs.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2001-0870

Produtos afetados

Alchemy Eye
Alchemy Network Monitor