PT-2005-5521 · Spectrum · Spectrum Cash Receipting System

Fredrik Hult

+1

·

Published

2005-12-31

·

Updated

2024-02-14

·

CVE-2005-4860

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Spectrum Cash Receipting System versions prior to 6.504
Description: The issue concerns the use of weak cryptography, specifically static substitution, in the PASSFILE password file. This weakness makes it easier for local users to gain privileges by decrypting a password.
Recommendations: For versions prior to 6.504, update to version 6.504 or later to resolve the issue. As a temporary workaround, consider restricting access to the PASSFILE password file to minimize the risk of exploitation.

Fix

Use of a Broken Cryptographic Algorithm

Weakness Enumeration

Related Identifiers

CVE-2005-4860

Affected Products

Spectrum Cash Receipting System