PT-2020-13736 · Mofi Network · Mofi4500-4Gxelte

Published

2020-09-03

·

Updated

2021-07-21

·

CVE-2020-13856

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mofi Network MOFI4500-4GXeLTE version 4.0.8-std
Description An issue was discovered where authentication is not required to download the support file, which contains sensitive information such as cleartext credentials and password hashes.
Recommendations For Mofi Network MOFI4500-4GXeLTE version 4.0.8-std, consider restricting access to the support file until a patch is available. As a temporary workaround, avoid downloading the support file to minimize the risk of exposing sensitive information. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-13856

Affected Products

Mofi4500-4Gxelte