CVE Vulnerabilities

CVE-2010-0598

Published: May 27, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Cisco Mediator Framework 1.5.1 before 1.5.1.build.14-eng, 2.2 before 2.2.1.dev.1, and 3.0 before 3.0.9.release.1 on the Cisco Network Building Mediator NBM-2400 and NBM-4800 and the Richards-Zeta Mediator 2500 does not encrypt HTTP sessions from operator workstations, which allows remote attackers to discover Administrator credentials by sniffing the network, aka Bug ID CSCtb83631.

Affected Software

NameVendorStart VersionEnd Version
Mediator_frameworkCisco1.5.1 (including)1.5.1 (including)
Mediator_frameworkCisco2.2 (including)2.2 (including)
Mediator_frameworkCisco3.0.8 (including)3.0.8 (including)

References