PT-2009-4787 · Kazakhnet · Tekradius
Tim Brown
·
Published
2009-07-07
·
Updated
2018-10-10
·
CVE-2009-2358
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
TekRADIUS version 3.0
Description
The issue concerns the permissions set for the TekRADIUS.ini file, which allows local users to read the file and obtain obfuscated database credentials.
Recommendations
For TekRADIUS version 3.0, consider changing the permissions of the TekRADIUS.ini file to restrict access and prevent local users from reading the file.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tekradius