Information Disclosure
Information disclosure results from unauthorized access. Possible causes of unauthorized access are as follows:
- Negligence in system configurations: For the sake of convenience, ME devices provide unauthorized login in certain scenarios. On the live network, unauthorized login, however, is still available.
- Negligence in management processes: For easy ME device deployment, a configuration file is usually used as the deployment template. Unauthorized access occurs if the administrator does not change the password for the administrator account.
- Defects in openness of IP networks: By deploying sniffers and interception devices, malicious users intercept and parse IP packets in transmission.
- Storage media: Boards or storage devices of a ME device are not encrypted when they are transferred.