PT-2015-4287 · Vdg Security · Vdg Security Sense

Stefan Viehböck

·

Publicado

2015-01-08

·

Atualizado

2015-01-08

·

CVE-2014-9577

CVSS v2.0

4.0

Média

VetorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions VDG Security SENSE (formerly DIVA) version 2.3.13
Description The issue allows remote authenticated users to obtain usernames and password hashes by logging in to the TCP port 51410 and reading the response. This occurs because the user database is sent when a user logs in.
Recommendations For VDG Security SENSE (formerly DIVA) version 2.3.13, consider restricting access to TCP port 51410 to minimize the risk of exploitation. As a temporary workaround, limit the ability of authenticated users to read the response containing the user database. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-9577

Produtos afetados

Vdg Security Sense