CVE-2013-4217: Low severity intel wimax network service vulnerability
InfraStack/OSDependent/Linux/OSAL/Services/wimaxosalcryptservices.c seems to write unencrypted passwords to the log file.
Other sources
The OSALCryptSetEncryptedPassword function in InfraStack/OSDependent/Linux/OSAL/Services/wimaxosalcryptservices.c in the OSAL crypt module in the Intel WiMAX Network Service through 1.5.2 for Intel Wireless WiMAX Connection 2400 devices logs a cleartext password during certain attempts to set a password, which allows local users to obtain sensitive information by reading a log file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4217?
CVE-2013-4217 is considered to have a medium severity due to the risk of exposing unencrypted passwords in log files.
How do I fix CVE-2013-4217?
To fix CVE-2013-4217, you should update to a version of Intel WiMAX Network Service later than 1.5.2.
Which software is affected by CVE-2013-4217?
CVE-2013-4217 affects Intel WiMAX Network Service versions 1.5.0 through 1.5.2.
What kind of vulnerability is CVE-2013-4217?
CVE-2013-4217 is a security vulnerability that involves logging unencrypted passwords, potentially leading to unauthorized access.
When was CVE-2013-4217 published?
CVE-2013-4217 was published in the year 2013.