CVE-2009-2272

Severity CVSS v4.0:
Pending analysis
Type:
CWE-312 Cleartext Storage of Sensitive Information
Publication date:
01/07/2009
Last modified:
13/02/2024

Description

The Huawei D100 stores the administrator's account name and password in cleartext in a cookie, which allows context-dependent attackers to obtain sensitive information by (1) reading a cookie file, by (2) sniffing the network for HTTP headers, and possibly by using unspecified other vectors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:huawei:d100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:huawei:d100:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools