PT-2005-3964 · Procom · Procom Netforce 800

Bambenek

·

Published

2005-10-05

·

Updated

2024-01-25

·

CVE-2005-3140

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Procom NetFORCE 800 version 4.02 M10 Build 20 and possibly other versions
Description The issue allows remote attackers to obtain cleartext NIS password hashes because the NIS password map (passwd.nis) is sent as a file attachment in diagnostic e-mail messages.
Recommendations For version 4.02 M10 Build 20 and possibly other versions, consider disabling the feature that sends diagnostic e-mail messages with the NIS password map as a file attachment until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2005-3140

Affected Products

Procom Netforce 800