PT-2020-13736 · Mofi Network · Mofi4500-4Gxelte
Published
2020-09-03
·
Updated
2021-07-21
·
CVE-2020-13856
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Mofi Network MOFI4500-4GXeLTE version 4.0.8-std
Description
An issue was discovered where authentication is not required to download the support file, which contains sensitive information such as cleartext credentials and password hashes.
Recommendations
For Mofi Network MOFI4500-4GXeLTE version 4.0.8-std, consider restricting access to the support file until a patch is available. As a temporary workaround, avoid downloading the support file to minimize the risk of exposing sensitive information. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mofi4500-4Gxelte