VYPR
Unrated severityNVD Advisory· Published Jan 23, 2020· Updated Aug 5, 2024

CVE-2019-19898

CVE-2019-19898

Description

In IXP EasyInstall 6.2.13723, there are cleartext credentials in network communication on TCP port 20050 when using the Administrator console remotely.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IXP EasyInstall 6.2.13723 transmits Administrator console credentials in cleartext over TCP port 20050, enabling network eavesdropping.

Vulnerability

In IXP EasyInstall version 6.2.13723, the Administrator console transmits authentication credentials in cleartext over TCP port 20050 [1]. The vulnerability exists in the network communication channel used when managing the software remotely, allowing any party with network access to observe credentials without encryption [1].

Exploitation

An attacker with network access to the TCP 20050 port can passively capture cleartext credentials during legitimate Administrator console sessions [1]. No authentication is required to intercept the traffic, and the attacker only needs to be positioned on a network segment where the traffic is visible (e.g., same local network, or via ARP spoofing) [1].

Impact

Successful exploitation results in disclosure of cleartext credentials used for administrative access to the IXP EasyInstall system [1]. An attacker can then use these credentials to gain unauthorized administrative access, potentially compromising the entire installation and related managed endpoints [1].

Mitigation

The vendor has not released a public fix for this vulnerability as of the publication date [1]. As a workaround, network administrators can restrict access to TCP port 20050 to trusted hosts only, or use VPNs and network segmentation to prevent eavesdropping [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.