VulnerabilityModified
CVE-2011-2223
The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 sends the Admin LDAP password in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.
MEDIUM 5.0EPSS 1.37%
Does this matter?
Lower severity and a low EPSS score (1.37%). Track it; it rarely justifies an emergency change on its own.
Description
The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 sends the Admin LDAP password in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.37% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-310
- Affected
- novell/data synchronizer · novell/mobility pack
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/45527Vendor Advisory
- http://www.novell.com/support/viewContent.do?externalId=7009055Vendor Advisory
- http://www.securityfocus.com/bid/49069
- http://secunia.com/advisories/45527Vendor Advisory
- http://www.novell.com/support/viewContent.do?externalId=7009055Vendor Advisory
- http://www.securityfocus.com/bid/49069
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.