SolarWinds Virtualization Manager 6.3.1 and earlier uses weak encryption to store passwords in /etc/shadow, which allows local users with superuser privileges to obtain user passwords via a brute force attack.
References
Configurations
History
21 Nov 2024, 02:54
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/137525/Solarwinds-Virtualization-Manager-6.3.1-Weak-Crypto.html - | |
References | () http://seclists.org/fulldisclosure/2016/Jun/38 - |
Information
Published : 2016-06-24 17:59
Updated : 2024-11-21 02:54
NVD link : CVE-2016-5709
Mitre link : CVE-2016-5709
CVE.ORG link : CVE-2016-5709
JSON object : View
Products Affected
solarwinds
- virtualization_manager
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor