EntryPass N5200 Active Network Control Panel allows remote attackers to read device memory and obtain the administrator username and password via a URL starting with an ASCII character o through z or A through D, different vectors than CVE-2014-8868.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://www.redteam-pentesting.de/advisories/rt-sa-2014-011 | exploit |
http://seclists.org/fulldisclosure/2014/Dec/2 | exploit mailing list |
http://www.securityfocus.com/archive/1/534128/100/0/threaded | mailing list |