USB Pratirodh is prone to sensitive information disclosure. It stores sensitive information such as username and password in simple usb.xml. An attacker with physical access to the system can modify the file according his own requirements that may aid in further attack.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/141651/USB-Pratirodh-Insecure-Password-Storage.html | Third Party Advisory VDB Entry |
http://seclists.org/fulldisclosure/2017/Mar/43 | Third Party Advisory VDB Entry |
http://www.securityfocus.com/archive/1/540289/100/0/threaded | |
http://www.securityfocus.com/bid/96970 | Third Party Advisory VDB Entry |
http://packetstormsecurity.com/files/141651/USB-Pratirodh-Insecure-Password-Storage.html | Third Party Advisory VDB Entry |
http://seclists.org/fulldisclosure/2017/Mar/43 | Third Party Advisory VDB Entry |
http://www.securityfocus.com/archive/1/540289/100/0/threaded | |
http://www.securityfocus.com/bid/96970 | Third Party Advisory VDB Entry |
Configurations
History
21 Nov 2024, 03:30
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/141651/USB-Pratirodh-Insecure-Password-Storage.html - Third Party Advisory, VDB Entry | |
References | () http://seclists.org/fulldisclosure/2017/Mar/43 - Third Party Advisory, VDB Entry | |
References | () http://www.securityfocus.com/archive/1/540289/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/96970 - Third Party Advisory, VDB Entry |
Information
Published : 2017-03-23 20:59
Updated : 2024-11-21 03:30
NVD link : CVE-2017-6911
Mitre link : CVE-2017-6911
CVE.ORG link : CVE-2017-6911
JSON object : View
Products Affected
usb_pratirodh_project
- usb_pratirodh
CWE
CWE-922
Insecure Storage of Sensitive Information