Lucene search

K
cveMitreCVE-2001-0133
HistoryMar 12, 2001 - 5:00 a.m.

CVE-2001-0133

2001-03-1205:00:00
mitre
web.nvd.nist.gov
26
interscan viruswall
vulnerability
cve-2001-0133
password expose
lack of encryption

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.8

Confidence

Low

EPSS

0.003

Percentile

70.8%

The web administration interface for Interscan VirusWall 3.6.x and earlier does not use encryption, which could allow remote attackers to obtain the administrator password to sniff the administrator password via the setpasswd.cgi program or other HTTP GET requests that contain base64 encoded usernames and passwords.

Affected configurations

Nvd
Node
trend_microinterscan_viruswallRange3.6
OR
trend_microinterscan_viruswallMatch3.0.1
VendorProductVersionCPE
trend_microinterscan_viruswall*cpe:2.3:a:trend_micro:interscan_viruswall:*:*:*:*:*:*:*:*
trend_microinterscan_viruswall3.0.1cpe:2.3:a:trend_micro:interscan_viruswall:3.0.1:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.8

Confidence

Low

EPSS

0.003

Percentile

70.8%

Related for CVE-2001-0133