PT-2024-4580 · Unknown · Sinec Traffic Analyzer

Published

2024-06-11

·

Updated

2024-08-06

·

CVE-2024-35208

CVSS v3.1

6.3

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: SINEC Traffic Analyzer versions prior to V1.2
Description: A vulnerability has been identified in the web server of SINEC Traffic Analyzer, where passwords are stored in cleartext. This could allow an attacker in a privileged position to obtain access passwords. The issue is related to insufficient protection of registration data, which may enable an attacker to gain unauthorized access to passwords and elevate their privileges.
Recommendations: For versions prior to V1.2, consider restricting access to the web server or implementing additional security measures to protect registration data until a fix is available. As a temporary workaround, avoid using the web server for sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-05086
CVE-2024-35208

Affected Products

Sinec Traffic Analyzer