Cisco Mediator Framework 1.5.1 before 1.5.1.build.14-eng, 2.2 before 2.2.1.dev.1, and 3.0 before 3.0.9.release.1 on the Cisco Network Building Mediator NBM-2400 and NBM-4800 and the Richards-Zeta Mediator 2500 does not properly restrict network access to an unspecified configuration file, which allows remote attackers to read passwords and unspecified other account details via a (1) XML RPC or (2) XML RPC over HTTPS session, aka Bug ID CSCtb83512.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://securitytracker.com/id?1024027 | vdb entry |
http://www.securityfocus.com/bid/40384 | vdb entry |
http://www.cisco.com/en/US/products/products_security_advisory09186a0080b2c518.shtml | patch vendor advisory |
http://www.us-cert.gov/control_systems/pdf/ICSA-10-147-01_Cisco_Network_Building_Mediator.pdf | |
http://www.kb.cert.org/vuls/id/757804 | third party advisory us government resource |
http://secunia.com/advisories/39904 | third party advisory |