PT-2006-3026 · Netaccess · Netaccess Na75

Publicado

2006-04-26

·

Atualizado

2018-10-18

·

CVE-2006-2045

CVSS v2.0

3.6

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions NetAccess NA75 version na-img-4.0.34.bin
Description The issue concerns the NetAccess NA75, specifically the na-img-4.0.34.bin version. There are two main problems: the shadow password file has world-readable permissions, allowing local users to view encrypted passwords, and the NetAccess database file has world-readable and writable permissions. This enables local users to not only view sensitive information but also modify data.
Recommendations For version na-img-4.0.34.bin, consider changing the permissions of the shadow password file to restrict access, and modify the NetAccess database file permissions to prevent unauthorized reading and writing. As a temporary workaround, restrict local user access to these files until a more permanent solution is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-2045

Produtos afetados

Netaccess Na75