PT-2005-3964 · Procom · Procom Netforce 800
Bambenek
·
Published
2005-10-05
·
Updated
2024-01-25
·
CVE-2005-3140
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Procom NetFORCE 800 version 4.02 M10 Build 20 and possibly other versions
Description
The issue allows remote attackers to obtain cleartext NIS password hashes because the NIS password map (passwd.nis) is sent as a file attachment in diagnostic e-mail messages.
Recommendations
For version 4.02 M10 Build 20 and possibly other versions, consider disabling the feature that sends diagnostic e-mail messages with the NIS password map as a file attachment until a fix is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Procom Netforce 800