The administration feature of the WaveNet IP 2400/2458 family Command Module requires a username and password for user authentication. These are transmitted on the nework as cleartext, permitting anyone with a protocol analyzer to compromise the units' security. Furthermore, there is no default restriction on the number of login attempts, permitting a brute-force attack on the username/password combination.
The administration feature of the WaveNet IP 2400/2458 family Command Module requires a username and password for user authentication. These are transmitted on the nework as cleartext, permitting anyone with a protocol analyzer to compromise the units' security. Furthermore, there is no default restriction on the number of login attempts, permitting a brute-force attack on the username/password combination.