CVE-2002-1949

HIGH

Iomega NAS A300U Firmware - Cleartext Transmission of Sensitive Information

Title source: llm
STIX 2.1

Description

The Network Attached Storage (NAS) Administration Web Page for Iomega NAS A300U transmits passwords in cleartext, which allows remote attackers to sniff the administrative password.

References (3)

Core 3
Core References
Broken Link vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/10521.php
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/6092
Broken Link mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2002-10/0440.html

Scores

CVSS v3 7.5
EPSS 0.0120
EPSS Percentile 64.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-319
Status published
Products (1)
iomega/nas_a300u_firmware
Published Dec 31, 2002
Tracked Since Feb 18, 2026