CVE-2018-5552

Versions of DocuTrac QuicDoc and Office Therapy that ship with DTISQLInstaller.exe version 1.6.4.0 and prior contains a hard-coded cryptographic salt, "S@l+&pepper".
Configurations

Configuration 1 (hide)

cpe:2.3:a:docutracinc:dtisqlinstaller:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:09

Type Values Removed Values Added
CVSS v2 : 2.1
v3 : 3.3
v2 : 2.1
v3 : 2.9
References () https://blog.rapid7.com/2018/03/14/r7-2018-01-cve-2018-5551-cve-2018-5552-docutrac-office-therapy-installer-hard-coded-credentials-and-cryptographic-salt/ - Exploit, Third Party Advisory () https://blog.rapid7.com/2018/03/14/r7-2018-01-cve-2018-5551-cve-2018-5552-docutrac-office-therapy-installer-hard-coded-credentials-and-cryptographic-salt/ - Exploit, Third Party Advisory

Information

Published : 2018-03-19 15:29

Updated : 2024-11-21 04:09


NVD link : CVE-2018-5552

Mitre link : CVE-2018-5552

CVE.ORG link : CVE-2018-5552


JSON object : View

Products Affected

docutracinc

  • dtisqlinstaller
CWE
CWE-760

Use of a One-Way Hash with a Predictable Salt

CWE-798

Use of Hard-coded Credentials