Procom NetFORCE 800 4.02 M10 Build 20 and possibly other versions sends the NIS password map (passwd.nis) as a file attachment in diagnostic e-mail messages, which allows remote attackers to obtain the cleartext NIS password hashes.
References
Link | Resource |
---|---|
http://marc.info/?l=bugtraq&m=112818351032426&w=2 | Mailing List Third Party Advisory |
http://secunia.com/advisories/17033/ | Broken Link Vendor Advisory |
http://www.securityfocus.com/bid/14997 | Broken Link Third Party Advisory VDB Entry |
http://marc.info/?l=bugtraq&m=112818351032426&w=2 | Mailing List Third Party Advisory |
http://secunia.com/advisories/17033/ | Broken Link Vendor Advisory |
http://www.securityfocus.com/bid/14997 | Broken Link Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 00:01
Type | Values Removed | Values Added |
---|---|---|
References | () http://marc.info/?l=bugtraq&m=112818351032426&w=2 - Mailing List, Third Party Advisory | |
References | () http://secunia.com/advisories/17033/ - Broken Link, Vendor Advisory | |
References | () http://www.securityfocus.com/bid/14997 - Broken Link, Third Party Advisory, VDB Entry |
25 Jan 2024, 20:58
Type | Values Removed | Values Added |
---|---|---|
First Time |
Procom netforce 800
Procom Procom netforce 800 Firmware |
|
References | (BUGTRAQ) http://marc.info/?l=bugtraq&m=112818351032426&w=2 - Mailing List, Third Party Advisory | |
References | (SECUNIA) http://secunia.com/advisories/17033/ - Broken Link, Vendor Advisory | |
References | (BID) http://www.securityfocus.com/bid/14997 - Broken Link, Third Party Advisory, VDB Entry | |
CWE | CWE-319 | |
CVSS |
v2 : v3 : |
v2 : 5.0
v3 : 7.5 |
CPE | cpe:2.3:h:procom:netforce_800:-:*:*:*:*:*:*:* cpe:2.3:o:procom:netforce_800_firmware:4.02:m10:*:*:*:*:*:* |
Information
Published : 2005-10-05 21:02
Updated : 2024-11-21 00:01
NVD link : CVE-2005-3140
Mitre link : CVE-2005-3140
CVE.ORG link : CVE-2005-3140
JSON object : View
Products Affected
procom
- netforce_800
- netforce_800_firmware
CWE
CWE-319
Cleartext Transmission of Sensitive Information