Verax NMS contains a flaw that may lead to unauthorized disclosure of potentially sensitive information. The issue is due to the NMS console leaking a plaintext file that contains connection details. This may allow an unprivileged remote attacker to gain access to connection detail information for arbitrary services and applications monitored by the server.
Disclosure Timeline:
Vendor Informed Date :2013-01-10
Vendor Ack Date :2013-01-11
Vendor Solution Date :2013-02-20
Disclosure Date :2013-03-07
Exploit Publish Date :2013-03-07