PT-2015-4287 · Vdg Security · Vdg Security Sense
Stefan Viehböck
·
Published
2015-01-08
·
Updated
2015-01-08
·
CVE-2014-9577
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
VDG Security SENSE (formerly DIVA) version 2.3.13
Description
The issue allows remote authenticated users to obtain usernames and password hashes by logging in to the TCP port 51410 and reading the response. This occurs because the user database is sent when a user logs in.
Recommendations
For VDG Security SENSE (formerly DIVA) version 2.3.13, consider restricting access to TCP port 51410 to minimize the risk of exploitation. As a temporary workaround, limit the ability of authenticated users to read the response containing the user database. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vdg Security Sense