PT-2015-6584 · Zoho · Zoho Netflow Analyzer
Published
2015-06-09
·
Updated
2016-12-31
·
CVE-2015-4418
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Zoho NetFlow Analyzer versions prior to build 10250
Description
The issue makes it easier for remote attackers to obtain access by leveraging an unattended workstation, as the password field lacks an off autocomplete attribute.
Recommendations
For versions prior to build 10250, update to a version that includes the off autocomplete attribute for the password field to prevent unauthorized access.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zoho Netflow Analyzer