PT-2001-2631 · Pathways · Pathways Homecare
CVE-2001-1546
·
Publicado
2001-12-31
·
Atualizado
2025-01-16
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Pathways Homecare version 6.5
Description
The issue concerns the use of weak encryption for user names and passwords. This weakness allows local users to gain privileges by recovering the passwords from the pwhc.ini file.
Recommendations
For Pathways Homecare version 6.5, consider changing the passwords and storing them securely to prevent unauthorized access until a more robust encryption method is implemented. As a temporary workaround, restrict access to the pwhc.ini file to minimize the risk of exploitation.
Exploit
Correção
Inadequate Encryption Strength
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Pathways Homecare