CVE-2002-0235
Castelle FaxPress, possibly 6.3 and other versions, when configured to use the Network print queue, allows attackers to obtain the username and password by submitting an incorrect login, which causes Faxpress to leak the correct username and password in…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.32%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Castelle FaxPress, possibly 6.3 and other versions, when configured to use the Network print queue, allows attackers to obtain the username and password by submitting an incorrect login, which causes Faxpress to leak the correct username and password in plaintext in an error event.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.32% probability · 69th percentile
- CISA KEV
- Not listed
- Affected
- castelle/faxpress
- Source
- cve@mitre.org
References
- http://online.securityfocus.com/archive/1/254168Patch, Vendor Advisory
- http://www.iss.net/security_center/static/8086.phpVendor Advisory
- http://www.securityfocus.com/bid/4030Vendor Advisory
- http://online.securityfocus.com/archive/1/254168Patch, Vendor Advisory
- http://www.iss.net/security_center/static/8086.phpVendor Advisory
- http://www.securityfocus.com/bid/4030Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.