The BreakingPoint Storm appliance before 3.0 requires cleartext credentials for establishing a session from a GUI administrative client, which allows remote attackers to obtain sensitive information by sniffing the network for XML documents.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.kb.cert.org/vuls/id/MAPG-8GANCC | us government resource |
http://www.kb.cert.org/vuls/id/520430 | third party advisory us government resource |
http://www.secureworks.com/research/advisories/SWRX-2012-006/ |