PT-2013-5981 · Dell · Dell Quest One Password Manager

Publicado

2013-10-24

·

Atualizado

2013-10-24

·

CVE-2013-6246

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Dell Quest One Password Manager version 5.0
Description The issue allows remote attackers to bypass CAPTCHA protections and obtain sensitive information, such as a user's full name, by sending a login request with a valid domain and username but without the CaptchaType, UseCaptchaEveryTime, and CaptchaResponse parameters.
Recommendations For version 5.0, consider temporarily disabling the login functionality until a patch is available, or restrict access to the login API endpoint to minimize the risk of exploitation. Avoid using the login feature without proper CAPTCHA validation until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-6246

Produtos afetados

Dell Quest One Password Manager