VulnerabilityModified
CVE-2004-2049
eSeSIX Thintune thin clients running firmware 2.4.38 and earlier store sensitive usernames and passwords in cleartext in configuration files for the keeper library, which allows attackers to gain access.
MEDIUM 4.6EPSS 0.36%
Does this matter?
Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.
Description
eSeSIX Thintune thin clients running firmware 2.4.38 and earlier store sensitive usernames and passwords in cleartext in configuration files for the keeper library, which allows attackers to gain access.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.36% probability · 29th percentile
- CISA KEV
- Not listed
- Affected
- esesix/thintune extreme · esesix/thintune l · esesix/thintune m · esesix/thintune mobile · esesix/thintune s · esesix/thintune xm · esesix/thintune xs
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=109068491801021&w=2
- http://secunia.com/advisories/12154
- http://securitytracker.com/id?1010770
- http://www.osvdb.org/8247
- http://www.securityfocus.com/bid/10794
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16795
- http://marc.info/?l=bugtraq&m=109068491801021&w=2
- http://secunia.com/advisories/12154
- http://securitytracker.com/id?1010770
- http://www.osvdb.org/8247
- http://www.securityfocus.com/bid/10794
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16795
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.