PT-2004-2945 · Esesix · Esesix Thintune
Dirk Loss
·
Published
2004-12-31
·
Updated
2017-07-11
·
CVE-2004-2049
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
eSeSIX Thintune thin clients versions 2.4.38 and earlier
Description
The issue allows attackers to gain access by storing sensitive usernames and passwords in cleartext in configuration files for the keeper library.
Recommendations
For versions 2.4.38 and earlier, update the firmware to a version that does not store sensitive information in cleartext, or consider restricting access to the configuration files of the keeper library until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Esesix Thintune