Vulnerability CVE-2004-2052


Published: 2004-12-31   Modified: 2012-02-12

Description:
eSeSIX Thintune thin clients running firmware 2.4.38 and earlier accept any password that begins with the actual password, which makes it easier for users to conduct brute force password guessing.

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Esesix -> Thintune 

 References:
http://marc.theaimsgroup.com/?l=bugtraq&m=109068491801021&w=2

Copyright 2024, cxsecurity.com

 

Back to Top