First published: Wed Sep 10 2014(Updated: )
The NETGEAR ProSafe Plus Configuration Utility creates configuration backup files containing cleartext passwords, which might allow remote attackers to obtain sensitive information by reading a file.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear Prosafe Firmware | <=6.1.0.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4864 is considered a high severity vulnerability due to the exposure of cleartext passwords.
To fix CVE-2014-4864, update your NETGEAR ProSafe Plus Configuration Utility to a version newer than 6.1.0.12.
CVE-2014-4864 exposes sensitive information such as configuration backup files containing cleartext passwords.
CVE-2014-4864 affects users of the NETGEAR ProSafe Plus Configuration Utility with firmware versions up to 6.1.0.12.
Yes, CVE-2014-4864 can be exploited remotely, allowing attackers to read cleartext password files.