PT-2004-2457 · Activepost · Activepost Standard

Luigi Auriemma

·

Published

2004-12-31

·

Updated

2017-07-11

·

CVE-2004-1549

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions ActivePost Standard version 3.1
Description The issue allows remote attackers to gain sensitive information by sniffing the network connection, as the conference menu in ActivePost Standard sends passwords of password-protected rooms in cleartext.
Recommendations For ActivePost Standard version 3.1, consider restricting access to password-protected rooms until a fix is available, and avoid using the conference menu feature to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1549

Affected Products

Activepost Standard