Vulnerability Details CVE-2004-2397
The web-based Management Console in Blue Coat Security Gateway OS 3.0 through 3.1.3.13 and 3.2.1, when importing a private key, stores the key and its passphrase in plaintext in a log file, which allows attackers to steal digital certificates.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 56.1%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2004-2397
-
cpe:2.3:o:broadcom:bluecoat_security_gateway:3.0
-
cpe:2.3:o:broadcom:bluecoat_security_gateway:3.1
-
cpe:2.3:o:broadcom:bluecoat_security_gateway:3.1.2
-
cpe:2.3:o:broadcom:bluecoat_security_gateway:3.1.2.2
-
cpe:2.3:o:broadcom:bluecoat_security_gateway:3.1.3.13
-
cpe:2.3:o:broadcom:bluecoat_security_gateway:3.1.3.2
-
cpe:2.3:o:broadcom:bluecoat_security_gateway:3.1.3.7
-
cpe:2.3:o:broadcom:bluecoat_security_gateway:3.2.1