PT-2001-2250 · Snapstream · Snapstream Pvs

Published

2001-07-26

·

Updated

2017-12-19

·

CVE-2001-1107

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions SnapStream PVS version 1.2a
Description The issue allows a remote attacker to gain privileges on the server because SnapStream PVS stores its passwords in plaintext in the file SSD.ini.
Recommendations For SnapStream PVS version 1.2a, consider restricting access to the SSD.ini file to minimize the risk of exploitation. As a temporary workaround, avoid using plaintext passwords in the SSD.ini file until a more secure method of password storage is implemented.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-1107

Affected Products

Snapstream Pvs