PT-2007-1441 · Dreameesoft · Dreameesoft Password Master
Published
2007-03-10
·
Updated
2008-09-05
·
CVE-2006-7163
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
DreameeSoft Password Master version 1.0
Description
The issue allows attackers with physical access to read the database contents due to the database being stored in an unencrypted format when the master password is set. This is possible via an unspecified authentication bypass.
Recommendations
For DreameeSoft Password Master version 1.0, consider encrypting the database or using an alternative password management solution that stores data securely. As a temporary workaround, restrict physical access to devices where the software is installed to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dreameesoft Password Master