PT-1999-1675 · Softarc · Softarc Firstclass Internet Server

Published

1999-08-30

·

Updated

2016-10-18

·

CVE-1999-1354

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Softarc FirstClass Internet Server versions 5.506 and earlier
Description: The e-mail client in the affected software stores usernames and passwords in cleartext in various files, including home.fc for version 5.506, network.fc for version 3.5, or FCCLIENT.LOG when logging is enabled.
Recommendations: For Softarc FirstClass Internet Server versions 5.506 and earlier, consider disabling the storage of usernames and passwords in cleartext as a temporary workaround until a patch is available. Restrict access to the files home.fc, network.fc, and FCCLIENT.LOG to minimize the risk of exploitation. Avoid using the logging feature until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-1999-1354

Affected Products

Softarc Firstclass Internet Server