First published: Thu Apr 11 2019(Updated: )
The Boa server configuration on DASAN H660RM devices with firmware 1.03-0022 logs POST data to the /tmp/boa-temp file, which allows logged-in users to read the credentials of administration web interface users.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dasannetworks H660rm Firmware | =1.03-0022 | |
Dasannetworks H660rm | ||
All of | ||
Dasannetworks H660rm Firmware | =1.03-0022 | |
Dasannetworks H660rm |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9976 has a medium severity rating due to its potential to expose sensitive user credentials.
To fix CVE-2019-9976, upgrade the firmware of your DASAN H660RM devices to a version higher than 1.03-0022.
CVE-2019-9976 affects DASAN H660RM devices running firmware version 1.03-0022.
CVE-2019-9976 exposes POST data including credentials to the administration web interface.
Any logged-in user on the DASAN H660RM device can potentially exploit CVE-2019-9976 to access sensitive information.