SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2004-2049

eSeSIX Thintune thin clients running firmware 2.4.38 and earlier store sensitive usernames and passwords in cleartext in configuration files for the keeper library, which allows attackers to gain access.

MEDIUM 4.6EPSS 0.36%

Does this matter?

Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.

Description

eSeSIX Thintune thin clients running firmware 2.4.38 and earlier store sensitive usernames and passwords in cleartext in configuration files for the keeper library, which allows attackers to gain access.

CVSS 2.0
4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
EPSS
0.36% probability · 29th percentile
CISA KEV
Not listed
Affected
esesix/thintune extreme · esesix/thintune l · esesix/thintune m · esesix/thintune mobile · esesix/thintune s · esesix/thintune xm · esesix/thintune xs
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.