PT-2015-4289 · Vdg Security · Vdg Security Sense
Stefan Viehböck
·
Publicado
2015-01-08
·
Atualizado
2015-01-08
·
CVE-2014-9579
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
VDG Security SENSE (formerly DIVA) version 2.3.13
Description
The issue allows attackers to obtain sensitive information by reading the plugin configuration files, as administrator credentials are stored in cleartext.
Recommendations
For VDG Security SENSE (formerly DIVA) version 2.3.13, consider updating the storage of administrator credentials to a more secure method, such as encryption, to prevent unauthorized access to sensitive information. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Vdg Security Sense