PT-2006-5400 · Microsoft+1 · Windows Mobile+1

Jonathan Read

·

Published

2006-09-07

·

Updated

2018-10-17

·

CVE-2006-4614

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions PDAapps Verichat for Pocket PC version 1.30bh
Description The issue allows local users to obtain sensitive information because usernames and passwords are stored in plaintext in the Windows Mobile registry. This can be accessed via keys under HKEY CURRENT USERSoftwarePDAappsVeriChat.
Recommendations For PDAapps Verichat for Pocket PC version 1.30bh, consider restricting access to the Windows Mobile registry to minimize the risk of exploitation. As a temporary workaround, avoid using the application until a secure method of storing usernames and passwords is implemented. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-4614

Affected Products

Pdaapps Verichat For Pocket Pc
Windows Mobile