EntryPass N5200 Active Network Control Panel does not properly restrict access, which allows remote attackers to obtain the administrator username and password, and possibly other sensitive information, via a request to /4.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://www.redteam-pentesting.de/advisories/rt-sa-2014-011 | exploit |
http://seclists.org/fulldisclosure/2014/Dec/2 | mailing list exploit |
http://www.securityfocus.com/archive/1/534128/100/0/threaded | mailing list |