PT-2006-5400 · Microsoft+1 · Windows Mobile+1
Jonathan Read
·
Published
2006-09-07
·
Updated
2018-10-17
·
CVE-2006-4614
CVSS v2.0
4.9
Medium
| Vector | AV:L/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
PDAapps Verichat for Pocket PC version 1.30bh
Description
The issue allows local users to obtain sensitive information because usernames and passwords are stored in plaintext in the Windows Mobile registry. This can be accessed via keys under HKEY CURRENT USERSoftwarePDAappsVeriChat.
Recommendations
For PDAapps Verichat for Pocket PC version 1.30bh, consider restricting access to the Windows Mobile registry to minimize the risk of exploitation. As a temporary workaround, avoid using the application until a secure method of storing usernames and passwords is implemented. At the moment, there is no information about a newer version that contains a fix for this issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pdaapps Verichat For Pocket Pc
Windows Mobile