First published: Fri Dec 31 2004(Updated: )
The make_recovery command for the TFTP server in HP Ignite-UX before C.6.2.241 makes a copy of the password file in the TFTP directory tree, which allows remote attackers to obtain sensitive information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HP Ignite-UX | =c.6.2.241 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0951 is considered to have a moderate severity level due to its potential to expose sensitive information.
To fix CVE-2004-0951, you should upgrade to HP Ignite-UX version C.6.2.241 or later.
CVE-2004-0951 is an information disclosure vulnerability that allows remote attackers to access sensitive files.
CVE-2004-0951 affects users of HP Ignite-UX version C.6.2.241 or earlier.
The impact of CVE-2004-0951 is that it can allow unauthorized access to the password file, leading to potential credential theft.