PT-2002-3067 · NetGear · Netgear Fm114P
Published
2002-12-31
·
Updated
2008-09-05
·
CVE-2002-2355
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Netgear FM114P firmware version 1.3
Description
The issue concerns the storage of sensitive information in cleartext when the wireless firewall is configured to backup configuration information. This could allow local users to obtain sensitive information, including DDNS (DynDNS) user name and password, MAC address filtering table, and possibly other information.
Recommendations
For Netgear FM114P firmware version 1.3, consider disabling the configuration backup feature until a secure method of storing sensitive information is implemented. Restrict access to the configuration information to minimize the risk of exploitation. Avoid using the backup feature for sensitive information until the issue is resolved.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netgear Fm114P