Local attacker can obtain sensitive information via debug interface in QED ResourceXpress Qubi3 devices

Local attacker can obtain sensitive information via debug interface in QED ResourceXpress Qubi3 devices

CVE-2020-25746 · MEDIUM Severity

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

QED ResourceXpress Qubi3 devices before 1.40.9 could allow a local attacker (with physical access to the device) to obtain sensitive information via the debug interface (keystrokes over a USB cable), aka wireless password visibility.

Learn more about our Physical Security Assessment.