MEDIUM · 4.6

CVE-2004-2049

eSeSIX Thintune thin clients running firmware 2.4.38 and earlier store sensitive usernames and passwords in cleartext in configuration files for the keeper library, which allows attackers to gain acce...

Vulnerability Description

eSeSIX Thintune thin clients running firmware 2.4.38 and earlier store sensitive usernames and passwords in cleartext in configuration files for the keeper library, which allows attackers to gain access.

CVSS Score

4.6

MEDIUM

AV:L/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
EsesixThintune Extreme2.4.38
EsesixThintune L2.4.38
EsesixThintune M2.4.38
EsesixThintune Mobile2.4.38
EsesixThintune S2.4.38
EsesixThintune Xm2.4.38
EsesixThintune Xs2.4.38

References

FAQ

What is CVE-2004-2049?

CVE-2004-2049 is a vulnerability with a CVSS score of 4.6 (MEDIUM). eSeSIX Thintune thin clients running firmware 2.4.38 and earlier store sensitive usernames and passwords in cleartext in configuration files for the keeper library, which allows attackers to gain acce...

How severe is CVE-2004-2049?

CVE-2004-2049 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-2049?

Check the references section above for vendor advisories and patch information. Affected products include: Esesix Thintune Extreme, Esesix Thintune L, Esesix Thintune M, Esesix Thintune Mobile, Esesix Thintune S.