3com RAS 1500 Configuration Disclosure

This script is Copyright (C) 2003-2016 Tenable Network Security, Inc.

Synopsis :

The remote host is susceptible to an information disclosure attack.

Description :

The remote 3com SuperStack II Remote Access System 1500 discloses
its user configuration (user_settings.cfg) when the file is
requested through the web interface. The file is transmitted in
cleartext and contains the password of the device as well as other
sensitive information.

An attacker may use this flaw to gain the control of this host.

See also :


Solution :

Filter incoming traffic to this host.

Risk factor :

Medium / CVSS Base Score : 5.0
CVSS Temporal Score : 5.0
Public Exploit Available : true

Family: Misc.

Nessus Plugin ID: 11480 (3com_config_disclosure.nasl)

Bugtraq ID: 7176


Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now