CVE-2019-17393
Summary
| CVE | CVE-2019-17393 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-10-18 17:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | The Customer's Tomedo Server in Version 1.7.3 communicates to the Vendor Tomedo Server via HTTP (in cleartext) that can be sniffed by unauthorized actors. Basic authentication is used for the authentication, making it possible to base64 decode the sniffed credentials and discover the username and password. |
Risk And Classification
Problem Types: CWE-319 | CWE-522
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Full Disclosure: Tomedo Server - Weak encryption mech. | FULLDISC | seclists.org | Mailing List, Third Party Advisory |
| Tomedo Server 1.7.3 Information Disclosure / Weak Cryptography ≈ Packet Storm | MISC | packetstormsecurity.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.