vendor:
PIPA C211
by:
Jerzy Kramarz
7,5
CVSS
HIGH
Credential Retrieval
200
CWE
Product Name: PIPA C211
Affected Version From: Soft Rev: SR1.1, HW Rev: PIPA C211 rev2
Affected Version To: Soft Rev: SR1.1, HW Rev: PIPA C211 rev2
Patch Exists: NO
Related CWE: CVE-2014-2046
CPE: h:broadcom:pipa_c211
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2014
Unauthenticated Credential And Configuration Retrieval In Broadcom Ltd PIPA C211
By sending the following request to the BROADCOM PIPA C211 web interface it is possible to retrieve complete system configuration including administrative credentials, SMTP community strings, FTP upload credentials and all other system user credentials.
Mitigation:
N/A