First published: Mon Oct 13 2008(Updated: )
Windows Mobile 6 on the HTC Hermes device makes WLAN passwords available to an auto-completion mechanism for the password input field, which allows physically proximate attackers to bypass password authentication and obtain WLAN access.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HTC Hermes | ||
Windows Mobile Connectivity Tools | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4540 is considered a medium severity vulnerability due to the potential for unauthorized WLAN access.
CVE-2008-4540 allows attackers to access WLAN passwords through an auto-completion mechanism, facilitating password authentication bypass.
Users of Windows Mobile 6 on HTC Hermes devices are specifically vulnerable to CVE-2008-4540.
To mitigate CVE-2008-4540, consider disabling auto-completion for password fields and securing physical access to devices.
CVE-2008-4540 is a software issue related to Windows Mobile 6 on the HTC Hermes device.