HTTP: 3Com 3crwe754g72-a Configuration File Download

This signature detects attempts to download the configuration file from a 3Com 3crwe754g72-a based device. Attackers can use the sensitive information obtained from the configuration file to gain full control over the device.

Extended Description

If an attacker attempts to log in as administrator at the same time as another administrator is logged in, 3crwe754g72-a provides the attacker with enough information to allow them to obtain the device's configuration file, which contains the administrator's password in plain text.

Short Name
HTTP:3COM:CONF-DOWNLOAD
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
3Com 3crwe754g72-a Configuration Download File
Release Date
10/21/2004
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown

Found a potential security threat?