PT-2001-2250 · Snapstream · Snapstream Pvs

Publicado

2001-07-26

·

Atualizado

2017-12-19

·

CVE-2001-1107

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions SnapStream PVS version 1.2a
Description The issue allows a remote attacker to gain privileges on the server because SnapStream PVS stores its passwords in plaintext in the file SSD.ini.
Recommendations For SnapStream PVS version 1.2a, consider restricting access to the SSD.ini file to minimize the risk of exploitation. As a temporary workaround, avoid using plaintext passwords in the SSD.ini file until a more secure method of password storage is implemented.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2001-1107

Produtos afetados

Snapstream Pvs