Castelle Faxpress Plaintext Password Disclosure Vulnerability
BID:4030
Info
Castelle Faxpress Plaintext Password Disclosure Vulnerability
| Bugtraq ID: | 4030 |
| Class: | Design Error |
| CVE: |
CVE-2002-0235 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 05 2002 12:00AM |
| Updated: | Jul 11 2009 09:56AM |
| Credit: | Discovered by Leon Ward <[email protected]>. |
| Vulnerable: |
Castelle FaxPress Software 6.3 |
| Not Vulnerable: | |
Discussion
Castelle Faxpress Plaintext Password Disclosure Vulnerability
Castelle FaxPress is an integrated solution for a network fax environment. FaxPress is a hardware and software server providing fax functionality, and is designed to integrate with Microsoft Windows, Novell NetWare, and Linux based systems.
When a network print job is submitted with an incorrect password, the FaxPress notice system is used to send an error message back to the client. This message includes the submitted username and password in plaintext, possibly leading to the disclosure of sensitive information.
Castelle FaxPress is an integrated solution for a network fax environment. FaxPress is a hardware and software server providing fax functionality, and is designed to integrate with Microsoft Windows, Novell NetWare, and Linux based systems.
When a network print job is submitted with an incorrect password, the FaxPress notice system is used to send an error message back to the client. This message includes the submitted username and password in plaintext, possibly leading to the disclosure of sensitive information.
Exploit / POC
Castelle Faxpress Plaintext Password Disclosure Vulnerability
No exploit code is required.
No exploit code is required.
Solution / Fix
Castelle Faxpress Plaintext Password Disclosure Vulnerability
Solution:
It has been reported that this issue will be fixed in the next version of the FaxPress software.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It has been reported that this issue will be fixed in the next version of the FaxPress software.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Castelle Faxpress Plaintext Password Disclosure Vulnerability
References:
References:
- FaxPress Product Page (Castelle)