VULNERABILITY INTELLIGENCE
CVE-2014-9596
CVSS score4.3 NONE
EPSS probability0.73%
CISA KEVNot currently listed
Published2015-01-15
Last modified2026-06-17
CVSS vectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Description
Panasonic Arbitrator Back-End Server (BES) MK 2.0 VPU before 9.3.1 build 4.08.003.0, when USB Wi-Fi or Direct LAN is enabled, and MK 3.0 VPU before 9.3.1 build 5.06.000.0, when Embedded Wi-Fi or Direct LAN is enabled, does not use encryption, which allows remote attackers to obtain sensitive information by sniffing the network for client-server traffic, as demonstrated by Active Directory credential information.
Weakness classification
- nvd@nist.gov: CWE-310
Primary references
- cve@mitre.org — Vendor Advisory
- cve@mitre.org — Third Party Advisory, US Government Resource
- af854a3a-2127-422b-91ae-364da2661108 — Vendor Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Third Party Advisory, US Government Resource