Lucene search

K
cve[email protected]CVE-2009-4197
HistoryDec 04, 2009 - 11:30 a.m.

CVE-2009-4197

2009-12-0411:30:00
web.nvd.nist.gov
22
huawei
mt882
v100r002b020
arg-t
firmware
vulnerability
autocomplete
nvd

4.7 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:C/I:N/A:N

6.5 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

rpwizPppoe.htm in Huawei MT882 V100R002B020 ARG-T running firmware 3.7.9.98 contains a form that does not disable the autocomplete setting for the password parameter, which makes it easier for local users or physically proximate attackers to obtain the password from web browsers that support autocomplete.

Affected configurations

NVD
Node
huaweimt882_v100t002b020_arg-tMatchfirmware_3.7.9.98
Node
huaweimt882_modem_firmwareMatch3.7.9.98
AND
huaweimt882_modemMatchv100r002b020_arg-t

4.7 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:C/I:N/A:N

6.5 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

Related for CVE-2009-4197