Skip to main content

Password in Configuration File

CVE-2014-5400

Severity Medium
Score 6.8/10

Summary

The installation component in Hospira MedNet before 6.1 places cleartext credentials in configuration files, which allows local users to obtain sensitive information by reading a file.

  • LOW
  • LOCAL
  • SINGLE
  • COMPLETE
  • COMPLETE
  • COMPLETE

CWE-260 - Password in Configuration File

The software stores a password in a configuration file that might be accessible to actors who do not know the password.

References

Advisory Timeline

  • Published