CVE-2010-3122
The DevonIT thin-client management tool relies on a shared secret for authentication but transmits the secret in cleartext, which makes it easier for remote attackers to discover the secret value, and consequently obtain administrative control over…
Does this matter?
Lower severity and a low EPSS score (1.38%). Track it; it rarely justifies an emergency change on its own.
Description
The DevonIT thin-client management tool relies on a shared secret for authentication but transmits the secret in cleartext, which makes it easier for remote attackers to discover the secret value, and consequently obtain administrative control over client machines, by sniffing the network.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.38% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-255
- Affected
- devonit/thin-client management tool
- Source
- cve@mitre.org
References
- http://www.kb.cert.org/vuls/id/278785US Government Resource
- http://www.kb.cert.org/vuls/id/278785US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.