VulnerabilityModified
CVE-2012-2963
The administrative interface in the embedded web server on the BreakingPoint Storm appliance before 3.0 does not require authentication for the gwt/BugReport script, which allows remote attackers to obtain sensitive information by downloading a .tgz file.
MEDIUM 5.0EPSS 1.81%
Does this matter?
Lower severity and a low EPSS score (1.81%). Track it; it rarely justifies an emergency change on its own.
Description
The administrative interface in the embedded web server on the BreakingPoint Storm appliance before 3.0 does not require authentication for the gwt/BugReport script, which allows remote attackers to obtain sensitive information by downloading a .tgz file.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.81% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- breakingpointsystems/breakingpoint storm appliance ctm · breakingpointsystems/breakingpoint storm appliance
- Source
- cret@cert.org
References
- http://www.kb.cert.org/vuls/id/520430US Government Resource
- http://www.kb.cert.org/vuls/id/MAPG-8GANCC
- http://www.secureworks.com/research/advisories/SWRX-2012-005/
- http://www.kb.cert.org/vuls/id/520430US Government Resource
- http://www.kb.cert.org/vuls/id/MAPG-8GANCC
- http://www.secureworks.com/research/advisories/SWRX-2012-005/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.