Iomega NAS A300U Plaintext NAS Administration Credentials Vulnerability
BID:6092
Info
Iomega NAS A300U Plaintext NAS Administration Credentials Vulnerability
| Bugtraq ID: | 6092 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 01 2002 12:00AM |
| Updated: | Nov 01 2002 12:00AM |
| Credit: | Discovery of this issue is credited to "Keith R. Watson" <[email protected]>. |
| Vulnerable: |
Iomega NAS A300U |
| Not Vulnerable: | |
Discussion
Iomega NAS A300U Plaintext NAS Administration Credentials Vulnerability
Iomega NAS A300U is reported to send NAS administrative authentication credentials in plaintext across the network. The credentials may be disclosed to attackers with the ability to intercept network traffic, which may enable them to gain unauthorized access to the NAS administrative interface.
This issue was reported for Iomega NAS A300U on Unix platforms. Other platforms and Iomega devices may also be affected.
Iomega NAS A300U is reported to send NAS administrative authentication credentials in plaintext across the network. The credentials may be disclosed to attackers with the ability to intercept network traffic, which may enable them to gain unauthorized access to the NAS administrative interface.
This issue was reported for Iomega NAS A300U on Unix platforms. Other platforms and Iomega devices may also be affected.
Exploit / POC
Iomega NAS A300U Plaintext NAS Administration Credentials Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
Iomega NAS A300U Plaintext NAS Administration Credentials Vulnerability
Solution:
It has been reported that the vendor has confirmed the issue and that solutions which address the problem are pending.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It has been reported that the vendor has confirmed the issue and that solutions which address the problem are pending.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Iomega NAS A300U Plaintext NAS Administration Credentials Vulnerability
References:
References:
- Iomega Homepage (Iomega)
- Iomega NAS A300U security and inter-operability issues ("Keith R. Watson"
)