Cleartext transmission of sensitive information in Engineer's Toolset (ETS) - CVE-2021-35246
Published: November 24, 2022
Engineer's Toolset (ETS)
SolarWinds
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due the application fails to prevent users from connecting to it over unencrypted connections. A remote attacker can with ability to intercept a legitimate user's network traffic can bypass the application's use of SSL/TLS encryption, and use the application as a platform for attacks against its users.