PT-2019-15126 · Tomedo · Tomedo Server

Chris Hein

·

Publicado

2019-10-18

·

Atualizado

2021-07-21

·

CVE-2019-17393

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tomedo Server version 1.7.3
Description The issue concerns the communication between the Customer's Tomedo Server and the Vendor Tomedo Server, which occurs over HTTP in cleartext. This makes it possible for unauthorized actors to intercept the communication. The use of basic authentication allows attackers to base64 decode the intercepted credentials, potentially revealing the username and password.
Recommendations For Tomedo Server version 1.7.3, consider disabling the use of basic authentication over HTTP until a secure alternative, such as HTTPS, can be implemented to encrypt the communication and protect the credentials. As a temporary workaround, restrict access to the Tomedo Server to minimize the risk of unauthorized interception.

Correção

Insufficiently Protected Credentials

Cleartext Transmission of Sensitive Information

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-17393

Produtos afetados

Tomedo Server