Lucene search

K
cveMitreCVE-2007-6096
HistoryNov 22, 2007 - 12:46 a.m.

CVE-2007-6096

2007-11-2200:46:00
CWE-255
mitre
web.nvd.nist.gov
20
ingate firewall
siparator
cve-2007-6096
cleartext password storage
security vulnerability

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.5

Confidence

Low

EPSS

0.004

Percentile

74.1%

Ingate Firewall before 4.6.0 and SIParator before 4.6.0 use cleartext storage for passwords of “administrators with less privileges,” which might allow attackers to read these passwords via unknown vectors.

Affected configurations

Nvd
Node
ingateingate_firewallRange4.5.2
OR
ingateingate_siparatorRange4.5.2
VendorProductVersionCPE
ingateingate_firewall*cpe:2.3:h:ingate:ingate_firewall:*:*:*:*:*:*:*:*
ingateingate_siparator*cpe:2.3:h:ingate:ingate_siparator:*:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.5

Confidence

Low

EPSS

0.004

Percentile

74.1%

Related for CVE-2007-6096