First published: Wed May 10 2006(Updated: )
The web management interface in 3Com TippingPoint SMS Server before 2.2.1.4478 does not restrict access to certain directories, which might allow remote attackers to obtain potentially sensitive information such as configuration settings.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
3Com TippingPoint SMS Server | <=2.2.1.4477 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0993 is considered a medium severity vulnerability due to the potential exposure of sensitive information.
To fix CVE-2006-0993, upgrade to 3Com TippingPoint SMS Server version 2.2.1.4478 or later.
CVE-2006-0993 may allow remote attackers to access sensitive configuration settings, compromising system integrity.
CVE-2006-0993 affects 3Com TippingPoint SMS Server versions prior to 2.2.1.4478.
Yes, CVE-2006-0993 can be exploited remotely by attackers due to insufficient access restrictions in the web management interface.