PT-2012-4396 · Ixia · Breakingpoint Storm Appliance
Jeff Jarmoc
·
Published
2012-08-12
·
Updated
2012-08-13
·
CVE-2012-2963
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
BreakingPoint Storm appliance versions prior to 3.0
Description
The administrative interface in the embedded web server does not require authentication for the gwt/BugReport script, allowing remote attackers to obtain sensitive information by downloading a .tgz file.
Recommendations
For versions prior to 3.0, update to version 3.0 or later to resolve the issue.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Breakingpoint Storm Appliance