Lucene search

K
cve[email protected]CVE-2014-0347
HistoryApr 12, 2014 - 4:37 a.m.

CVE-2014-0347

2014-04-1204:37:31
CWE-255
web.nvd.nist.gov
24
cve-2014-0347
websense
triton
unified security center
cleartext password
disclosure
vulnerability

3.5 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

6.3 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

47.9%

The Settings module in Websense Triton Unified Security Center 7.7.3 before Hotfix 31, Web Filter 7.7.3 before Hotfix 31, Web Security 7.7.3 before Hotfix 31, Web Security Gateway 7.7.3 before Hotfix 31, and Web Security Gateway Anywhere 7.7.3 before Hotfix 31 allows remote authenticated users to read cleartext passwords by replacing type=β€œpassword” with type=β€œtext” in an INPUT element in the (1) Log Database or (2) User Directories component.

Affected configurations

NVD
Node
websensetriton_unified_security_centerMatch7.7.3
OR
websensetriton_web_filterMatch7.7.3
OR
websensetriton_web_securityMatch7.7.3
OR
websensetriton_web_security_gatewayMatch7.7.3
OR
websensetriton_web_security_gateway_anywhereMatch7.7.3

3.5 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

6.3 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

47.9%

Related for CVE-2014-0347