← volver
CVE-2021-4471

TG8 Firewall Unauthenticated User Password Disclosure

CVSS 8.7 HIGHEPSS 0.6%CWE-538
TG8 Firewall exposes a directory such as /data/ over HTTP without authentication. This directory stores credential files for previously logged-in users. A remote unauthenticated attacker can enumerate and download files within the directory to obtain valid account usernames and passwords, leading to loss of confidentiality and further unauthorized access.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Productos afectados
TG8 · TG8 Firewall

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →