7.5
CVE-2021-27140
- EPSS 0.05%
- Veröffentlicht 10.02.2021 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:57:23
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to find passwords and authentication cookies stored in cleartext in the web.log HTTP logs.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fiberhome ≫ Hg6245d Firmware Version <= rp2613
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.05% | 0.108 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-312 Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.