CVE Vulnerabilities

CVE-2004-2049

Published: Dec 31, 2004 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

eSeSIX Thintune thin clients running firmware 2.4.38 and earlier store sensitive usernames and passwords in cleartext in configuration files for the keeper library, which allows attackers to gain access.

Affected Software

Name Vendor Start Version End Version
Thintune_extreme Esesix 2.4.38 (including) 2.4.38 (including)
Thintune_l Esesix 2.4.38 (including) 2.4.38 (including)
Thintune_m Esesix 2.4.38 (including) 2.4.38 (including)
Thintune_mobile Esesix 2.4.38 (including) 2.4.38 (including)
Thintune_s Esesix 2.4.38 (including) 2.4.38 (including)
Thintune_xm Esesix 2.4.38 (including) 2.4.38 (including)
Thintune_xs Esesix 2.4.38 (including) 2.4.38 (including)

References