PT-2011-4582 · Netsaro · Netsaro Enterprise Messenger Server

Published

2011-09-27

·

Updated

2012-05-21

·

CVE-2011-3692

CVSS v2.0

1.9

Low

VectorAV:L/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions NetSaro Enterprise Messenger Server version 2.0
Description The issue allows local users to obtain sensitive information by reading the configuration.xml file, which stores cleartext console credentials, and then performing a base64 decoding step.
Recommendations For NetSaro Enterprise Messenger Server version 2.0, consider encrypting or securely storing console credentials in the configuration.xml file to prevent unauthorized access. As a temporary workaround, restrict access to the configuration.xml file to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-3692

Affected Products

Netsaro Enterprise Messenger Server