CVE-2004-2455
Sweex Wireless Broadband Router/Accesspoint 802.11g (LC000060) allows remote attackers to obtain sensitive information and gain privileges by using TFTP to download the nvram file, then extracting the username, password, and other data from the file.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.70%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Sweex Wireless Broadband Router/Accesspoint 802.11g (LC000060) allows remote attackers to obtain sensitive information and gain privileges by using TFTP to download the nvram file, then extracting the username, password, and other data from the file.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.70% probability · 76th percentile
- CISA KEV
- Not listed
- Affected
- sweex/wireless broadband router accesspoint 802.11g
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0574.htmlVendor Advisory
- http://secunia.com/advisories/11603Vendor Advisory
- http://www.osvdb.org/6109
- http://www.securityfocus.com/bid/10339
- http://www.securitytracker.com/alerts/2004/May/1010143.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16140
- http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0574.htmlVendor Advisory
- http://secunia.com/advisories/11603Vendor Advisory
- http://www.osvdb.org/6109
- http://www.securityfocus.com/bid/10339
- http://www.securitytracker.com/alerts/2004/May/1010143.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16140
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.