CVE-2013-5582

Ammyy Admin 3.2 and earlier stores the client ID at a fixed memory location, which might make it easier for user-assisted remote attackers to bypass authentication by running a local program that extracts a field from the AA_v3.2.exe file.
References
Link Resource
http://www.securityfocus.com/archive/1/530827 Third Party Advisory VDB Entry
http://www.securityfocus.com/archive/1/530827 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:ammyy:ammyy_admin:*:*:*:*:*:*:*:*

History

21 Nov 2024, 01:57

Type Values Removed Values Added
References () http://www.securityfocus.com/archive/1/530827 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/archive/1/530827 - Third Party Advisory, VDB Entry

Information

Published : 2020-02-11 19:15

Updated : 2024-11-21 01:57


NVD link : CVE-2013-5582

Mitre link : CVE-2013-5582

CVE.ORG link : CVE-2013-5582


JSON object : View

Products Affected

ammyy

  • ammyy_admin
CWE
CWE-287

Improper Authentication