PT-2007-1441 · Dreameesoft · Dreameesoft Password Master

Published

2007-03-10

·

Updated

2008-09-05

·

CVE-2006-7163

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions DreameeSoft Password Master version 1.0
Description The issue allows attackers with physical access to read the database contents due to the database being stored in an unencrypted format when the master password is set. This is possible via an unspecified authentication bypass.
Recommendations For DreameeSoft Password Master version 1.0, consider encrypting the database or using an alternative password management solution that stores data securely. As a temporary workaround, restrict physical access to devices where the software is installed to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-7163

Affected Products

Dreameesoft Password Master