PT-2018-1195 · Mge · Mge Network Management Card Transverse

Ilya Karpov

·

Published

2018-03-15

·

Updated

2019-10-03

·

CVE-2018-7246

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions MGE Network Management Card Transverse versions 66074
Description The issue is related to the transmission of sensitive information in cleartext by the integrated web server of the affected device. This could allow a remote attacker to obtain administrative account data. The vulnerability is exploited through the web server, specifically when accessing the "Access Control" page, which may send account data in cleartext if SSL is not used in the device settings.
Recommendations For MGE Network Management Card Transverse version 66074, consider configuring the device to use SSL in its settings to encrypt the transmission of sensitive information. As a temporary workaround, restrict access to the "Access Control" page (IP-address device/ups/pas cont.htm) to minimize the risk of exploitation. Ensure that the integrated web server (Port 80/443/TCP) is properly secured to prevent unauthorized access.

Fix

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-00653
CVE-2018-7246

Affected Products

Mge Network Management Card Transverse